Skip to content
This page View Markdown Open in ChatGPT Open in Claude

Auth with AWS Cognito

Your app signs people in with Cognito and sends the token it gets to API Maker. An auth provider of type AWS checks the token with the keys of the user pool, finds the person in a table of yours, and runs the call with the groups of that person.

Page API Security → Auth Providers → type AWS.
Header x-aws-authorization: <Cognito token>
In code g.req.auth.authAWS : the opened token, and the columns selected from your table.
The provider
import * as T from 'types';

let awsTokenGenerator: T.IAuthTokenAWS & { name: string; testObj?: any; } = {
    name: 'aws_token_generator',
    cognitoUserPoolId: 'us-east-1_xxxxxx',
    region: 'us-east-1',
    tokenUse: 'access',                 // 'access' | 'id' : which Cognito token the app sends
    tokenExpiration: 3600000,           // milliseconds, at most 3600000
    sourceFieldOfUniqueId: 'sub',       // the claim which identifies the person
    groupsDataSource: { instance: 'mongodb', database: 'shop', collection: 'users', targetFieldForUniqueId: 'cognito_sub', groupsColumn: 'groups', select: { name: 1, email: 1 } },
};
module.exports = awsTokenGenerator;

The groups of the person

  • sourceFieldOfUniqueId is the claim of the token which identifies the person (an email, sub, oid).
  • groupsDataSource names the table of yours which holds that person : targetFieldForUniqueId is the column with the same value, groupsColumn the comma separated groups of the person, select the columns to put in g.req.auth.
  • Without groupsDataSource, the token is checked but the person gets no group of its own : only the API user decides.

Require it

  • authProviders: ['aws_token_generator'] in the settings of the APIs, tables or databases, or in common.authProviders of the secret.
  • The call carries the API user token in x-am-authorization and the token of the provider in x-aws-authorization.
  • testObj in the provider is the person the API testing page pretends to be.