openapi: 3.0.0 info: version: '2014-06-30' x-release: v4 title: 'Amazon Cognito Identity #X Amz Target=AWSCognitoIdentityProviderService.AddCustomAttributes #X Amz Target=AWSCognitoIdentityProviderService.AddCustomAttributes #X Amz Target=AWSCognitoIdentityProviderService.SetUserPoolMfaConfig API' description: Amazon Cognito Federated Identities

Amazon Cognito Federated Identities is a web service that delivers scoped temporary credentials to mobile devices and other untrusted environments. It uniquely identifies a device and supplies the user with a consistent identity over the lifetime of an application.

Using Amazon Cognito Federated Identities, you can enable authentication with one or more third-party identity providers (Facebook, Google, or Login with Amazon) or an Amazon Cognito user pool, and you can also choose to support unauthenticated access from your app. Cognito delivers a unique identifier for each user and acts as an OpenID token provider trusted by AWS Security Token Service (STS) to access temporary, limited-privilege AWS credentials.

For a description of the authentication flow from the Amazon Cognito Developer Guide see Authentication Flow.

For more information see Amazon Cognito Federated Identities.

x-logo: url: https://twitter.com/awscloud/profile_image?size=original backgroundColor: '#FFFFFF' termsOfService: https://aws.amazon.com/service-terms/ contact: name: Mike Ralphson email: mike.ralphson@gmail.com url: https://github.com/mermade/aws2openapi x-twitter: PermittedSoc license: name: Apache 2.0 License url: http://www.apache.org/licenses/ x-providerName: amazonaws.com x-serviceName: cognito-identity x-origin: - contentType: application/json url: https://raw.githubusercontent.com/aws/aws-sdk-js/master/apis/cognito-identity-2014-06-30.normal.json converter: url: https://github.com/mermade/aws2openapi version: 1.0.0 x-apisguru-driver: external x-apiClientRegistration: url: https://portal.aws.amazon.com/gp/aws/developer/registration/index.html?nc2=h_ct x-apisguru-categories: - cloud x-preferred: true servers: - url: http://cognito-identity.{region}.amazonaws.com variables: region: description: The AWS region enum: - us-east-1 - us-east-2 - us-west-1 - us-west-2 - us-gov-west-1 - us-gov-east-1 - ca-central-1 - eu-north-1 - eu-west-1 - eu-west-2 - eu-west-3 - eu-central-1 - eu-south-1 - af-south-1 - ap-northeast-1 - ap-northeast-2 - ap-northeast-3 - ap-southeast-1 - ap-southeast-2 - ap-east-1 - ap-south-1 - sa-east-1 - me-south-1 default: us-east-1 description: The Amazon Cognito Identity multi-region endpoint - url: https://cognito-identity.{region}.amazonaws.com variables: region: description: The AWS region enum: - us-east-1 - us-east-2 - us-west-1 - us-west-2 - us-gov-west-1 - us-gov-east-1 - ca-central-1 - eu-north-1 - eu-west-1 - eu-west-2 - eu-west-3 - eu-central-1 - eu-south-1 - af-south-1 - ap-northeast-1 - ap-northeast-2 - ap-northeast-3 - ap-southeast-1 - ap-southeast-2 - ap-east-1 - ap-south-1 - sa-east-1 - me-south-1 default: us-east-1 description: The Amazon Cognito Identity multi-region endpoint - url: http://cognito-identity.{region}.amazonaws.com.cn variables: region: description: The AWS region enum: - cn-north-1 - cn-northwest-1 default: cn-north-1 description: The Amazon Cognito Identity endpoint for China (Beijing) and China (Ningxia) - url: https://cognito-identity.{region}.amazonaws.com.cn variables: region: description: The AWS region enum: - cn-north-1 - cn-northwest-1 default: cn-north-1 description: The Amazon Cognito Identity endpoint for China (Beijing) and China (Ningxia) security: - hmac: [] tags: - name: '#X Amz Target=AWSCognitoIdentityProviderService.SetUserPoolMfaConfig' paths: /#X-Amz-Target=AWSCognitoIdentityProviderService.SetUserPoolMfaConfig: parameters: - $ref: '#/components/parameters/X-Amz-Content-Sha256' - $ref: '#/components/parameters/X-Amz-Date' - $ref: '#/components/parameters/X-Amz-Algorithm' - $ref: '#/components/parameters/X-Amz-Credential' - $ref: '#/components/parameters/X-Amz-Security-Token' - $ref: '#/components/parameters/X-Amz-Signature' - $ref: '#/components/parameters/X-Amz-SignedHeaders' post: operationId: SetUserPoolMfaConfig description:

Sets the user pool multi-factor authentication (MFA) configuration.

This action might generate an SMS text message. Starting June 1, 2021, US telecom carriers require you to register an origination phone number before you can send SMS messages to US phone numbers. If you use SMS text messages in Amazon Cognito, you must register a phone number with Amazon Pinpoint. Amazon Cognito uses the registered number automatically. Otherwise, Amazon Cognito users who must receive SMS messages might not be able to sign up, activate their accounts, or sign in.

If you have never used SMS text messages with Amazon Cognito or any other Amazon Web Service, Amazon Simple Notification Service might place your account in the SMS sandbox. In sandbox mode , you can send messages only to verified phone numbers. After you test your app while in the sandbox environment, you can move out of the sandbox and into production. For more information, see SMS message settings for Amazon Cognito user pools in the Amazon Cognito Developer Guide.

responses: '200': description: Success content: application/json: schema: $ref: '#/components/schemas/SetUserPoolMfaConfigResponse' examples: SetUserPoolMfaConfig200Example: summary: Default SetUserPoolMfaConfig 200 response x-microcks-default: true value: SmsMfaConfiguration: example SoftwareTokenMfaConfiguration: example MfaConfiguration: example '480': description: InvalidParameterException content: application/json: schema: $ref: '#/components/schemas/InvalidParameterException' examples: SetUserPoolMfaConfig480Example: summary: Default SetUserPoolMfaConfig 480 response x-microcks-default: true value: example '481': description: TooManyRequestsException content: application/json: schema: $ref: '#/components/schemas/TooManyRequestsException' examples: SetUserPoolMfaConfig481Example: summary: Default SetUserPoolMfaConfig 481 response x-microcks-default: true value: example '482': description: ResourceNotFoundException content: application/json: schema: $ref: '#/components/schemas/ResourceNotFoundException' examples: SetUserPoolMfaConfig482Example: summary: Default SetUserPoolMfaConfig 482 response x-microcks-default: true value: example '483': description: InvalidSmsRoleAccessPolicyException content: application/json: schema: $ref: '#/components/schemas/InvalidSmsRoleAccessPolicyException' examples: SetUserPoolMfaConfig483Example: summary: Default SetUserPoolMfaConfig 483 response x-microcks-default: true value: example '484': description: InvalidSmsRoleTrustRelationshipException content: application/json: schema: $ref: '#/components/schemas/InvalidSmsRoleTrustRelationshipException' examples: SetUserPoolMfaConfig484Example: summary: Default SetUserPoolMfaConfig 484 response x-microcks-default: true value: example '485': description: NotAuthorizedException content: application/json: schema: $ref: '#/components/schemas/NotAuthorizedException' examples: SetUserPoolMfaConfig485Example: summary: Default SetUserPoolMfaConfig 485 response x-microcks-default: true value: example '486': description: InternalErrorException content: application/json: schema: $ref: '#/components/schemas/InternalErrorException' examples: SetUserPoolMfaConfig486Example: summary: Default SetUserPoolMfaConfig 486 response x-microcks-default: true value: example requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/SetUserPoolMfaConfigRequest' parameters: - name: X-Amz-Target in: header required: true schema: type: string enum: - AWSCognitoIdentityProviderService.SetUserPoolMfaConfig summary: Amazon Cognito Set User Pool Mfa Config x-microcks-operation: delay: 0 dispatcher: FALLBACK tags: - '#X Amz Target=AWSCognitoIdentityProviderService.SetUserPoolMfaConfig' components: schemas: InvalidSmsRoleTrustRelationshipException: {} ResourceNotFoundException: {} BooleanType: type: boolean UserPoolMfaType: type: string enum: - 'OFF' - 'ON' - OPTIONAL InvalidParameterException: {} ArnType: type: string pattern: arn:[\w+=/,.@-]+:[\w+=/,.@-]+:([\w+=/,.@-]*)?:[0-9]+:[\w+=/,.@-]+(:[\w+=/,.@-]+)?(:[\w+=/,.@-]+)? minLength: 20 maxLength: 2048 SetUserPoolMfaConfigResponse: type: object properties: SmsMfaConfiguration: allOf: - $ref: '#/components/schemas/SmsMfaConfigType' - description: The SMS text message MFA configuration. SoftwareTokenMfaConfiguration: allOf: - $ref: '#/components/schemas/SoftwareTokenMfaConfigType' - description: The software token MFA configuration. MfaConfiguration: allOf: - $ref: '#/components/schemas/UserPoolMfaType' - description:

The MFA configuration. Valid values include:

RegionCodeType: type: string minLength: 5 maxLength: 32 SmsConfigurationType: type: object required: - SnsCallerArn properties: SnsCallerArn: allOf: - $ref: '#/components/schemas/ArnType' - description: 'The Amazon Resource Name (ARN) of the Amazon SNS caller. This is the ARN of the IAM role in your Amazon Web Services account that Amazon Cognito will use to send SMS messages. SMS messages are subject to a spending limit. ' ExternalId: allOf: - $ref: '#/components/schemas/StringType' - description:

The external ID provides additional security for your IAM role. You can use an ExternalId with the IAM role that you use with Amazon SNS to send SMS messages for your user pool. If you provide an ExternalId, your Amazon Cognito user pool includes it in the request to assume your IAM role. You can configure the role trust policy to require that Amazon Cognito, and any principal, provide the ExternalID. If you use the Amazon Cognito Management Console to create a role for SMS multi-factor authentication (MFA), Amazon Cognito creates a role with the required permissions and a trust policy that demonstrates use of the ExternalId.

For more information about the ExternalId of a role, see How to use an external ID when granting access to your Amazon Web Services resources to a third party

SnsRegion: allOf: - $ref: '#/components/schemas/RegionCodeType' - description:

The Amazon Web Services Region to use with Amazon SNS integration. You can choose the same Region as your user pool, or a supported Legacy Amazon SNS alternate Region.

Amazon Cognito resources in the Asia Pacific (Seoul) Amazon Web Services Region must use your Amazon SNS configuration in the Asia Pacific (Tokyo) Region. For more information, see SMS message settings for Amazon Cognito user pools.

description: The SMS configuration type is the settings that your Amazon Cognito user pool must use to send an SMS message from your Amazon Web Services account through Amazon Simple Notification Service. To send SMS messages with Amazon SNS in the Amazon Web Services Region that you want, the Amazon Cognito user pool uses an Identity and Access Management (IAM) role in your Amazon Web Services account. SmsMfaConfigType: type: object properties: SmsAuthenticationMessage: allOf: - $ref: '#/components/schemas/SmsVerificationMessageType' - description: The SMS authentication message that will be sent to users with the code they must sign in. The message must contain the β€˜{####}’ placeholder, which is replaced with the code. If the message isn't included, and default message will be used. SmsConfiguration: allOf: - $ref: '#/components/schemas/SmsConfigurationType' - description: The SMS configuration with the settings that your Amazon Cognito user pool must use to send an SMS message from your Amazon Web Services account through Amazon Simple Notification Service. To request Amazon SNS in the Amazon Web Services Region that you want, the Amazon Cognito user pool uses an Identity and Access Management (IAM) role that you provide for your Amazon Web Services account. description: The SMS text message multi-factor authentication (MFA) configuration type. StringType: type: string minLength: 0 maxLength: 131072 SetUserPoolMfaConfigRequest: type: object required: - UserPoolId title: SetUserPoolMfaConfigRequest properties: UserPoolId: allOf: - $ref: '#/components/schemas/UserPoolIdType' - description: The user pool ID. SmsMfaConfiguration: allOf: - $ref: '#/components/schemas/SmsMfaConfigType' - description: The SMS text message MFA configuration. SoftwareTokenMfaConfiguration: allOf: - $ref: '#/components/schemas/SoftwareTokenMfaConfigType' - description: The software token MFA configuration. MfaConfiguration: allOf: - $ref: '#/components/schemas/UserPoolMfaType' - description:

The MFA configuration. If you set the MfaConfiguration value to β€˜ON’, only users who have set up an MFA factor can sign in. To learn more, see Adding Multi-Factor Authentication (MFA) to a user pool. Valid values include:

UserPoolIdType: type: string pattern: '[\w-]+_[0-9a-zA-Z]+' minLength: 1 maxLength: 55 SmsVerificationMessageType: type: string pattern: .*\{####\}.* minLength: 6 maxLength: 140 SoftwareTokenMfaConfigType: type: object properties: Enabled: allOf: - $ref: '#/components/schemas/BooleanType' - description: Specifies whether software token MFA is activated. description: The type used for enabling software token MFA at the user pool level. InvalidSmsRoleAccessPolicyException: {} NotAuthorizedException: {} InternalErrorException: {} TooManyRequestsException: {} parameters: X-Amz-Content-Sha256: name: X-Amz-Content-Sha256 in: header schema: type: string required: false X-Amz-Date: name: X-Amz-Date in: header schema: type: string required: false X-Amz-Security-Token: name: X-Amz-Security-Token in: header schema: type: string required: false X-Amz-SignedHeaders: name: X-Amz-SignedHeaders in: header schema: type: string required: false X-Amz-Algorithm: name: X-Amz-Algorithm in: header schema: type: string required: false X-Amz-Signature: name: X-Amz-Signature in: header schema: type: string required: false X-Amz-Credential: name: X-Amz-Credential in: header schema: type: string required: false securitySchemes: hmac: type: apiKey name: Authorization in: header description: Amazon Signature authorization v4 x-amazon-apigateway-authtype: awsSigv4 externalDocs: description: Amazon Web Services documentation url: https://docs.aws.amazon.com/cognito-identity/ x-hasEquivalentPaths: true