I saw this article from AWS discussing about the client credentials grant: https://aws.amazon.com/blogs/mobile/understanding-amazon-cognito-user-pool-oauth-2-0-grants/. However, it's unclear to me that if an access token is generated from a different AWS account, how can it be trusted?
Let's say I have this scenario:
- My API is in AWS account A1 and I want to authenticate a client API from AWS account A2
- From the article, my client can configure their app client with Client Credentials flow.
- Then they can request an access token using a client secret and their token issuer, which stays on their AWS account.
- They send an API request to my API with the access token
- My API validates the token and responds to the request
The problem I have is in the last step above, my API in account A1 has a completely different issuer than the client service in account A2. How would I trust their token then?
One solution I can think of is to allow my client to register with me using their user pool ID, app ID and issuer URL. Then I can store the info in some database and use it to match their tokens for validation. Are there any features in AWS that can handle this situation for me without me having to create the extra logic?