Auth with AWS Cognito¶
Your app signs people in with Cognito and sends the token it gets to API Maker. An auth provider of type AWS checks the token with the keys of the user pool, finds the person in a table of yours, and runs the call with the groups of that person.
| Page | API Security → Auth Providers → type AWS. |
| Header | x-aws-authorization: <Cognito token> |
| In code | g.req.auth.authAWS : the opened token, and the columns selected from your table. |
The groups of the person¶
sourceFieldOfUniqueIdis the claim of the token which identifies the person (an email,sub,oid).groupsDataSourcenames the table of yours which holds that person :targetFieldForUniqueIdis the column with the same value,groupsColumnthe comma separated groups of the person,selectthe columns to put ing.req.auth.- Without
groupsDataSource, the token is checked but the person gets no group of its own : only the API user decides.
Require it¶
authProviders: ['aws_token_generator']in the settings of the APIs, tables or databases, or incommon.authProvidersof the secret.- The call carries the API user token in
x-am-authorizationand the token of the provider inx-aws-authorization. testObjin the provider is the person the API testing page pretends to be.