Lambda function is throwing congito-idb permission error

Viewed 32

I have a lambda function to check if the user exists in my Cognito. I am using Google OAuth in Cognito and have an API endpoint direct to lambda function on post route hit. The lambda function works right if I tried to invoke it locally. I tried to give all sorts of permission to the lambda function but still, it threw an error.

"message": "User: arn:aws:sts::XXXXXXXXXX:assumed-role/user-service-prod-ap-south-1-lambdaRole/user-service-prod-check is not authorized to perform: cognito-idp:AdminGetUser on resource: arn:aws:cognito-idp:ap-south-1:XXXXXXXXXX:userpool/ap-south-1_ZwSEBspSk because no identity-based policy allows the cognito-idp:AdminGetUser action",
"code": "AccessDeniedException",
"time": "2022-06-19T06:15:12.338Z",
"requestId": "66f2fba8-c106-450c-9d13-XXXXXXXXXX",
"statusCode": 400,
"retryable": false,
"retryDelay": 92.3532116696846

0 Answers
Related