AWS Cognito User Pool: How to map long attributes (>2048 characters) from OIDC Identity provider?

Viewed 239

We have Keycloak as AWS Cognito user pool IDP. Keycloak provides user attribute, which we need to store for user pool user as cognito custom attribute. Cognito custom attribute has length 2048 (cognito max length) and it is used later in Pre-Token Generation to create specific id_token claims.

In some cases Keycloak attribute can contain long values, since it is json data in encoded format. Is there any mechanism to provide custom mapping code (lambda?) which handles keycloak custom attribute parsing so we can strip unnecessary json elements from data and map only needed data to user pool attribute?

User pool triggers are not helpful here since they cannot modify IDP attributes before user pool user is created.

Error we get in cognito after Keycloak federated login is following:

String attributes cannot have a length of more than 2048

0 Answers
Related