I have been trying Cognito user pools with federated identities and identity pool. I created identity pool and assigned cognito as auth provider for it. Cognito has Google identity provider. I used Amplify to sign-up/sign-in, it's configured with Identity pool and my User pool. When I log in, identity is properly created in identity pool and linked to user in user pool. I can see identityId and identityPoolId in credentials available in Amplify session, both contain valid information, I was able to invoke Cognito sync and exchange identity data with no problem.
I have problem with identity sent to API Lambda handlers integrated via API Gateway. I use REST API (old one), integrate as Lambda Proxy and I created Lambda authorizer, which simply dumps event into log.
When I check CloudWatch logs, I see
"identity": {
"cognitoIdentityPoolId": null,
"accountId": null,
"cognitoIdentityId": null,
"caller": null,
"sourceIp": "185.5.69.158",
"principalOrgId": null,
"accessKey": null,
"cognitoAuthenticationType": null,
"cognitoAuthenticationProvider": null,
"userArn": null,
"userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36",
"user": null
},
Why us cognitoIdentityPoolId and cognitoIdentityId null? I use Amplify API integration and I see authorization header with pre-signed request in logs.
What is required to get access to identity in lambda authorizer?