openapi: 3.0.0
info:
version: '2014-06-30'
x-release: v4
title: 'Amazon Cognito Identity #X Amz Target=AWSCognitoIdentityProviderService.AddCustomAttributes #X Amz Target=AWSCognitoIdentityProviderService.AddCustomAttributes #X Amz Target=AWSCognitoIdentityProviderService.SetRiskConfiguration API'
description:
Amazon Cognito Federated Identities is a web service that delivers scoped temporary credentials to mobile devices and other untrusted environments. It uniquely identifies a device and supplies the user with a consistent identity over the lifetime of an application.
Using Amazon Cognito Federated Identities, you can enable authentication with one or more third-party identity providers (Facebook, Google, or Login with Amazon) or an Amazon Cognito user pool, and you can also choose to support unauthenticated access from your app. Cognito delivers a unique identifier for each user and acts as an OpenID token provider trusted by AWS Security Token Service (STS) to access temporary, limited-privilege AWS credentials.
For a description of the authentication flow from the Amazon Cognito Developer Guide see Authentication Flow.
For more information see Amazon Cognito Federated Identities.
x-logo: url: https://twitter.com/awscloud/profile_image?size=original backgroundColor: '#FFFFFF' termsOfService: https://aws.amazon.com/service-terms/ contact: name: Mike Ralphson email: mike.ralphson@gmail.com url: https://github.com/mermade/aws2openapi x-twitter: PermittedSoc license: name: Apache 2.0 License url: http://www.apache.org/licenses/ x-providerName: amazonaws.com x-serviceName: cognito-identity x-origin: - contentType: application/json url: https://raw.githubusercontent.com/aws/aws-sdk-js/master/apis/cognito-identity-2014-06-30.normal.json converter: url: https://github.com/mermade/aws2openapi version: 1.0.0 x-apisguru-driver: external x-apiClientRegistration: url: https://portal.aws.amazon.com/gp/aws/developer/registration/index.html?nc2=h_ct x-apisguru-categories: - cloud x-preferred: true servers: - url: http://cognito-identity.{region}.amazonaws.com variables: region: description: The AWS region enum: - us-east-1 - us-east-2 - us-west-1 - us-west-2 - us-gov-west-1 - us-gov-east-1 - ca-central-1 - eu-north-1 - eu-west-1 - eu-west-2 - eu-west-3 - eu-central-1 - eu-south-1 - af-south-1 - ap-northeast-1 - ap-northeast-2 - ap-northeast-3 - ap-southeast-1 - ap-southeast-2 - ap-east-1 - ap-south-1 - sa-east-1 - me-south-1 default: us-east-1 description: The Amazon Cognito Identity multi-region endpoint - url: https://cognito-identity.{region}.amazonaws.com variables: region: description: The AWS region enum: - us-east-1 - us-east-2 - us-west-1 - us-west-2 - us-gov-west-1 - us-gov-east-1 - ca-central-1 - eu-north-1 - eu-west-1 - eu-west-2 - eu-west-3 - eu-central-1 - eu-south-1 - af-south-1 - ap-northeast-1 - ap-northeast-2 - ap-northeast-3 - ap-southeast-1 - ap-southeast-2 - ap-east-1 - ap-south-1 - sa-east-1 - me-south-1 default: us-east-1 description: The Amazon Cognito Identity multi-region endpoint - url: http://cognito-identity.{region}.amazonaws.com.cn variables: region: description: The AWS region enum: - cn-north-1 - cn-northwest-1 default: cn-north-1 description: The Amazon Cognito Identity endpoint for China (Beijing) and China (Ningxia) - url: https://cognito-identity.{region}.amazonaws.com.cn variables: region: description: The AWS region enum: - cn-north-1 - cn-northwest-1 default: cn-north-1 description: The Amazon Cognito Identity endpoint for China (Beijing) and China (Ningxia) security: - hmac: [] tags: - name: '#X Amz Target=AWSCognitoIdentityProviderService.SetRiskConfiguration' paths: /#X-Amz-Target=AWSCognitoIdentityProviderService.SetRiskConfiguration: parameters: - $ref: '#/components/parameters/X-Amz-Content-Sha256' - $ref: '#/components/parameters/X-Amz-Date' - $ref: '#/components/parameters/X-Amz-Algorithm' - $ref: '#/components/parameters/X-Amz-Credential' - $ref: '#/components/parameters/X-Amz-Security-Token' - $ref: '#/components/parameters/X-Amz-Signature' - $ref: '#/components/parameters/X-Amz-SignedHeaders' post: operationId: SetRiskConfiguration description:Configures actions on detected risks. To delete the risk configuration for UserPoolId or ClientId, pass null values for all four configuration types.
To activate Amazon Cognito advanced security features, update the user pool to include the UserPoolAddOns keyAdvancedSecurityMode.
From parameter.
BlockEmail:
allOf:
- $ref: '#/components/schemas/NotifyEmailType'
- description: Email template used when a detected risk event is blocked.
NoActionEmail:
allOf:
- $ref: '#/components/schemas/NotifyEmailType'
- description: The email template used when a detected risk event is allowed.
MfaEmail:
allOf:
- $ref: '#/components/schemas/NotifyEmailType'
- description: The multi-factor authentication (MFA) email template used when MFA is challenged as part of a detected risk.
description: The notify configuration type.
UserPoolAddOnNotEnabledException: {}
AccountTakeoverActionsType:
type: object
properties:
LowAction:
allOf:
- $ref: '#/components/schemas/AccountTakeoverActionType'
- description: Action to take for a low risk.
MediumAction:
allOf:
- $ref: '#/components/schemas/AccountTakeoverActionType'
- description: Action to take for a medium risk.
HighAction:
allOf:
- $ref: '#/components/schemas/AccountTakeoverActionType'
- description: Action to take for a high risk.
description: Account takeover actions type.
RiskConfigurationType:
type: object
properties:
UserPoolId:
allOf:
- $ref: '#/components/schemas/UserPoolIdType'
- description: The user pool ID.
ClientId:
allOf:
- $ref: '#/components/schemas/ClientIdType'
- description: The app client ID.
CompromisedCredentialsRiskConfiguration:
allOf:
- $ref: '#/components/schemas/CompromisedCredentialsRiskConfigurationType'
- description: The compromised credentials risk configuration object, including the EventFilter and the EventAction.
AccountTakeoverRiskConfiguration:
allOf:
- $ref: '#/components/schemas/AccountTakeoverRiskConfigurationType'
- description: The account takeover risk configuration object, including the NotifyConfiguration object and Actions to take if there is an account takeover.
RiskExceptionConfiguration:
allOf:
- $ref: '#/components/schemas/RiskExceptionConfigurationType'
- description: The configuration to override the risk decision.
LastModifiedDate:
allOf:
- $ref: '#/components/schemas/DateType'
- description: The date and time, in ISO 8601 format, when the item was modified.
description: The risk configuration type.
EventFiltersType:
type: array
items:
$ref: '#/components/schemas/EventFilterType'
SetRiskConfigurationResponse:
type: object
required:
- RiskConfiguration
properties:
RiskConfiguration:
allOf:
- $ref: '#/components/schemas/RiskConfigurationType'
- description: The risk configuration.
StringType:
type: string
minLength: 0
maxLength: 131072
CompromisedCredentialsActionsType:
type: object
required:
- EventAction
properties:
EventAction:
allOf:
- $ref: '#/components/schemas/CompromisedCredentialsEventActionType'
- description: The event action.
description: The compromised credentials actions type.
SkippedIPRangeListType:
type: array
items:
$ref: '#/components/schemas/StringType'
maxItems: 200
EventFilterType:
type: string
enum:
- SIGN_IN
- PASSWORD_CHANGE
- SIGN_UP
UserPoolIdType:
type: string
pattern: '[\w-]+_[0-9a-zA-Z]+'
minLength: 1
maxLength: 55
AccountTakeoverActionType:
type: object
required:
- Notify
- EventAction
properties:
Notify:
allOf:
- $ref: '#/components/schemas/AccountTakeoverActionNotifyType'
- description: Flag specifying whether to send a notification.
EventAction:
allOf:
- $ref: '#/components/schemas/AccountTakeoverEventActionType'
- description: The action to take in response to the account takeover action. Valid values are as follows:
BLOCK Choosing this action will block the request.
MFA_IF_CONFIGURED Present an MFA challenge if user has configured it, else allow the request.
MFA_REQUIRED Present an MFA challenge if user has configured it, else block the request.
NO_ACTION Allow the user to sign in.
The app client ID. If ClientId is null, then the risk configuration is mapped to userPoolId. When the client ID is null, the same risk configuration is applied to all the clients in the userPool.
Otherwise, ClientId is mapped to the client. When the client ID isn't null, the user pool configuration is overridden and the risk configuration for the client is used instead.