openapi: 3.0.0 info: version: '2014-06-30' x-release: v4 title: 'Amazon Cognito Identity #X Amz Target=AWSCognitoIdentityProviderService.AddCustomAttributes #X Amz Target=AWSCognitoIdentityProviderService.AddCustomAttributes #X Amz Target=AWSCognitoIdentityService.DescribeIdentityPool API' description: Amazon Cognito Federated Identities

Amazon Cognito Federated Identities is a web service that delivers scoped temporary credentials to mobile devices and other untrusted environments. It uniquely identifies a device and supplies the user with a consistent identity over the lifetime of an application.

Using Amazon Cognito Federated Identities, you can enable authentication with one or more third-party identity providers (Facebook, Google, or Login with Amazon) or an Amazon Cognito user pool, and you can also choose to support unauthenticated access from your app. Cognito delivers a unique identifier for each user and acts as an OpenID token provider trusted by AWS Security Token Service (STS) to access temporary, limited-privilege AWS credentials.

For a description of the authentication flow from the Amazon Cognito Developer Guide see Authentication Flow.

For more information see Amazon Cognito Federated Identities.

x-logo: url: https://twitter.com/awscloud/profile_image?size=original backgroundColor: '#FFFFFF' termsOfService: https://aws.amazon.com/service-terms/ contact: name: Mike Ralphson email: mike.ralphson@gmail.com url: https://github.com/mermade/aws2openapi x-twitter: PermittedSoc license: name: Apache 2.0 License url: http://www.apache.org/licenses/ x-providerName: amazonaws.com x-serviceName: cognito-identity x-origin: - contentType: application/json url: https://raw.githubusercontent.com/aws/aws-sdk-js/master/apis/cognito-identity-2014-06-30.normal.json converter: url: https://github.com/mermade/aws2openapi version: 1.0.0 x-apisguru-driver: external x-apiClientRegistration: url: https://portal.aws.amazon.com/gp/aws/developer/registration/index.html?nc2=h_ct x-apisguru-categories: - cloud x-preferred: true servers: - url: http://cognito-identity.{region}.amazonaws.com variables: region: description: The AWS region enum: - us-east-1 - us-east-2 - us-west-1 - us-west-2 - us-gov-west-1 - us-gov-east-1 - ca-central-1 - eu-north-1 - eu-west-1 - eu-west-2 - eu-west-3 - eu-central-1 - eu-south-1 - af-south-1 - ap-northeast-1 - ap-northeast-2 - ap-northeast-3 - ap-southeast-1 - ap-southeast-2 - ap-east-1 - ap-south-1 - sa-east-1 - me-south-1 default: us-east-1 description: The Amazon Cognito Identity multi-region endpoint - url: https://cognito-identity.{region}.amazonaws.com variables: region: description: The AWS region enum: - us-east-1 - us-east-2 - us-west-1 - us-west-2 - us-gov-west-1 - us-gov-east-1 - ca-central-1 - eu-north-1 - eu-west-1 - eu-west-2 - eu-west-3 - eu-central-1 - eu-south-1 - af-south-1 - ap-northeast-1 - ap-northeast-2 - ap-northeast-3 - ap-southeast-1 - ap-southeast-2 - ap-east-1 - ap-south-1 - sa-east-1 - me-south-1 default: us-east-1 description: The Amazon Cognito Identity multi-region endpoint - url: http://cognito-identity.{region}.amazonaws.com.cn variables: region: description: The AWS region enum: - cn-north-1 - cn-northwest-1 default: cn-north-1 description: The Amazon Cognito Identity endpoint for China (Beijing) and China (Ningxia) - url: https://cognito-identity.{region}.amazonaws.com.cn variables: region: description: The AWS region enum: - cn-north-1 - cn-northwest-1 default: cn-north-1 description: The Amazon Cognito Identity endpoint for China (Beijing) and China (Ningxia) security: - hmac: [] tags: - name: '#X Amz Target=AWSCognitoIdentityService.DescribeIdentityPool' paths: /#X-Amz-Target=AWSCognitoIdentityService.DescribeIdentityPool: parameters: - $ref: '#/components/parameters/X-Amz-Content-Sha256' - $ref: '#/components/parameters/X-Amz-Date' - $ref: '#/components/parameters/X-Amz-Algorithm' - $ref: '#/components/parameters/X-Amz-Credential' - $ref: '#/components/parameters/X-Amz-Security-Token' - $ref: '#/components/parameters/X-Amz-Signature' - $ref: '#/components/parameters/X-Amz-SignedHeaders' post: operationId: DescribeIdentityPool description:

Gets details about a particular identity pool, including the pool name, ID description, creation date, and current number of users.

You must use AWS Developer credentials to call this API.

responses: '200': description: Success content: application/json: schema: $ref: '#/components/schemas/IdentityPool' examples: DescribeIdentityPool200Example: summary: Default DescribeIdentityPool 200 response x-microcks-default: true value: IdentityPoolId: example IdentityPoolName: example AllowUnauthenticatedIdentities: example AllowClassicFlow: example SupportedLoginProviders: example DeveloperProviderName: example OpenIdConnectProviderARNs: example CognitoIdentityProviders: example SamlProviderARNs: example IdentityPoolTags: example '480': description: InvalidParameterException content: application/json: schema: $ref: '#/components/schemas/InvalidParameterException' examples: DescribeIdentityPool480Example: summary: Default DescribeIdentityPool 480 response x-microcks-default: true value: example '481': description: ResourceNotFoundException content: application/json: schema: $ref: '#/components/schemas/ResourceNotFoundException' examples: DescribeIdentityPool481Example: summary: Default DescribeIdentityPool 481 response x-microcks-default: true value: example '482': description: NotAuthorizedException content: application/json: schema: $ref: '#/components/schemas/NotAuthorizedException' examples: DescribeIdentityPool482Example: summary: Default DescribeIdentityPool 482 response x-microcks-default: true value: example '483': description: TooManyRequestsException content: application/json: schema: $ref: '#/components/schemas/TooManyRequestsException' examples: DescribeIdentityPool483Example: summary: Default DescribeIdentityPool 483 response x-microcks-default: true value: example '484': description: InternalErrorException content: application/json: schema: $ref: '#/components/schemas/InternalErrorException' examples: DescribeIdentityPool484Example: summary: Default DescribeIdentityPool 484 response x-microcks-default: true value: example requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/DescribeIdentityPoolInput' parameters: - name: X-Amz-Target in: header required: true schema: type: string enum: - AWSCognitoIdentityService.DescribeIdentityPool summary: Amazon Cognito Describe Identity Pool x-microcks-operation: delay: 0 dispatcher: FALLBACK tags: - '#X Amz Target=AWSCognitoIdentityService.DescribeIdentityPool' components: parameters: X-Amz-Content-Sha256: name: X-Amz-Content-Sha256 in: header schema: type: string required: false X-Amz-Date: name: X-Amz-Date in: header schema: type: string required: false X-Amz-Security-Token: name: X-Amz-Security-Token in: header schema: type: string required: false X-Amz-SignedHeaders: name: X-Amz-SignedHeaders in: header schema: type: string required: false X-Amz-Algorithm: name: X-Amz-Algorithm in: header schema: type: string required: false X-Amz-Signature: name: X-Amz-Signature in: header schema: type: string required: false X-Amz-Credential: name: X-Amz-Credential in: header schema: type: string required: false schemas: ResourceNotFoundException: {} CognitoIdentityProvider: type: object properties: ProviderName: allOf: - $ref: '#/components/schemas/CognitoIdentityProviderName' - description: The provider name for an Amazon Cognito user pool. For example, cognito-idp.us-east-1.amazonaws.com/us-east-1_123456789. ClientId: allOf: - $ref: '#/components/schemas/CognitoIdentityProviderClientId' - description: The client ID for the Amazon Cognito user pool. ServerSideTokenCheck: allOf: - $ref: '#/components/schemas/CognitoIdentityProviderTokenCheck' - description:

TRUE if server-side token validation is enabled for the identity provider’s token.

Once you set ServerSideTokenCheck to TRUE for an identity pool, that identity pool will check with the integrated user pools to make sure that the user has not been globally signed out or deleted before the identity pool provides an OIDC token or AWS credentials for the user.

If the user is signed out or deleted, the identity pool will return a 400 Not Authorized error.

description: A provider representing an Amazon Cognito user pool and its client ID. IdentityPoolUnauthenticated: type: boolean IdentityPoolTagsType: type: object additionalProperties: $ref: '#/components/schemas/TagValueType' InvalidParameterException: {} DeveloperProviderName: type: string pattern: '[\w._-]+' minLength: 1 maxLength: 128 OIDCProviderList: type: array items: $ref: '#/components/schemas/ARNString' IdentityPoolId: type: string pattern: '[\w-]+:[0-9a-f-]+' minLength: 1 maxLength: 55 IdentityPool: type: object required: - IdentityPoolId - IdentityPoolName - AllowUnauthenticatedIdentities title: IdentityPool properties: IdentityPoolId: allOf: - $ref: '#/components/schemas/IdentityPoolId' - description: An identity pool ID in the format REGION:GUID. IdentityPoolName: allOf: - $ref: '#/components/schemas/IdentityPoolName' - description: A string that you provide. AllowUnauthenticatedIdentities: allOf: - $ref: '#/components/schemas/IdentityPoolUnauthenticated' - description: TRUE if the identity pool supports unauthenticated logins. AllowClassicFlow: allOf: - $ref: '#/components/schemas/ClassicFlow' - description: Enables or disables the Basic (Classic) authentication flow. For more information, see Identity Pools (Federated Identities) Authentication Flow in the Amazon Cognito Developer Guide. SupportedLoginProviders: allOf: - $ref: '#/components/schemas/IdentityProviders' - description: Optional key:value pairs mapping provider names to provider app IDs. DeveloperProviderName: allOf: - $ref: '#/components/schemas/DeveloperProviderName' - description: The "domain" by which Cognito will refer to your users. OpenIdConnectProviderARNs: allOf: - $ref: '#/components/schemas/OIDCProviderList' - description: The ARNs of the OpenID Connect providers. CognitoIdentityProviders: allOf: - $ref: '#/components/schemas/CognitoIdentityProviderList' - description: A list representing an Amazon Cognito user pool and its client ID. SamlProviderARNs: allOf: - $ref: '#/components/schemas/SAMLProviderList' - description: An array of Amazon Resource Names (ARNs) of the SAML provider for your identity pool. IdentityPoolTags: allOf: - $ref: '#/components/schemas/IdentityPoolTagsType' - description: The tags that are assigned to the identity pool. A tag is a label that you can apply to identity pools to categorize and manage them in different ways, such as by purpose, owner, environment, or other criteria. description: An object representing an Amazon Cognito identity pool. DescribeIdentityPoolInput: type: object required: - IdentityPoolId title: DescribeIdentityPoolInput properties: IdentityPoolId: allOf: - $ref: '#/components/schemas/IdentityPoolId' - description: An identity pool ID in the format REGION:GUID. description: Input to the DescribeIdentityPool action. CognitoIdentityProviderClientId: type: string pattern: '[\w_]+' minLength: 1 maxLength: 128 CognitoIdentityProviderList: type: array items: $ref: '#/components/schemas/CognitoIdentityProvider' CognitoIdentityProviderName: type: string pattern: '[\w._:/-]+' minLength: 1 maxLength: 128 CognitoIdentityProviderTokenCheck: type: boolean TagValueType: type: string minLength: 0 maxLength: 256 IdentityProviderId: type: string pattern: '[\w.;_/-]+' minLength: 1 maxLength: 128 ARNString: type: string minLength: 20 maxLength: 2048 NotAuthorizedException: {} InternalErrorException: {} ClassicFlow: type: boolean TooManyRequestsException: {} IdentityPoolName: type: string pattern: '[\w\s+=,.@-]+' minLength: 1 maxLength: 128 IdentityProviders: type: object maxProperties: 10 additionalProperties: $ref: '#/components/schemas/IdentityProviderId' SAMLProviderList: type: array items: $ref: '#/components/schemas/ARNString' securitySchemes: hmac: type: apiKey name: Authorization in: header description: Amazon Signature authorization v4 x-amazon-apigateway-authtype: awsSigv4 externalDocs: description: Amazon Web Services documentation url: https://docs.aws.amazon.com/cognito-identity/ x-hasEquivalentPaths: true