openapi: 3.0.0 info: version: 2014-06-30 x-release: v4 title: 'Amazon Cognito Identity #X Amz Target=AWSCognitoIdentityProviderService.AddCustomAttributes #X Amz Target=AWSCognitoIdentityProviderService.AddCustomAttributes #X Amz Target=AWSCognitoIdentityProviderService.GetUser API' description: Amazon Cognito Federated Identities

Amazon Cognito Federated Identities is a web service that delivers scoped temporary credentials to mobile devices and other untrusted environments. It uniquely identifies a device and supplies the user with a consistent identity over the lifetime of an application.

Using Amazon Cognito Federated Identities, you can enable authentication with one or more third-party identity providers (Facebook, Google, or Login with Amazon) or an Amazon Cognito user pool, and you can also choose to support unauthenticated access from your app. Cognito delivers a unique identifier for each user and acts as an OpenID token provider trusted by AWS Security Token Service (STS) to access temporary, limited-privilege AWS credentials.

For a description of the authentication flow from the Amazon Cognito Developer Guide see Authentication Flow.

For more information see Amazon Cognito Federated Identities.

x-logo: url: https://api.apis.guru/v2/cache/logo/https_twitter.com_awscloud_profile_image.png backgroundColor: '#FFFFFF' termsOfService: https://aws.amazon.com/service-terms/ contact: name: Mike Ralphson email: mike.ralphson@gmail.com url: https://github.com/mermade/aws2openapi x-twitter: PermittedSoc license: name: Apache 2.0 License url: http://www.apache.org/licenses/ x-providerName: amazonaws.com x-serviceName: cognito-identity x-origin: - contentType: application/json url: https://raw.githubusercontent.com/aws/aws-sdk-js/master/apis/cognito-identity-2014-06-30.normal.json converter: url: https://github.com/mermade/aws2openapi version: 1.0.0 x-apisguru-driver: external x-apiClientRegistration: url: https://portal.aws.amazon.com/gp/aws/developer/registration/index.html?nc2=h_ct x-apisguru-categories: - cloud x-preferred: true servers: - url: http://cognito-identity.{region}.amazonaws.com variables: region: description: The AWS region enum: - us-east-1 - us-east-2 - us-west-1 - us-west-2 - us-gov-west-1 - us-gov-east-1 - ca-central-1 - eu-north-1 - eu-west-1 - eu-west-2 - eu-west-3 - eu-central-1 - eu-south-1 - af-south-1 - ap-northeast-1 - ap-northeast-2 - ap-northeast-3 - ap-southeast-1 - ap-southeast-2 - ap-east-1 - ap-south-1 - sa-east-1 - me-south-1 default: us-east-1 description: The Amazon Cognito Identity multi-region endpoint - url: https://cognito-identity.{region}.amazonaws.com variables: region: description: The AWS region enum: - us-east-1 - us-east-2 - us-west-1 - us-west-2 - us-gov-west-1 - us-gov-east-1 - ca-central-1 - eu-north-1 - eu-west-1 - eu-west-2 - eu-west-3 - eu-central-1 - eu-south-1 - af-south-1 - ap-northeast-1 - ap-northeast-2 - ap-northeast-3 - ap-southeast-1 - ap-southeast-2 - ap-east-1 - ap-south-1 - sa-east-1 - me-south-1 default: us-east-1 description: The Amazon Cognito Identity multi-region endpoint - url: http://cognito-identity.{region}.amazonaws.com.cn variables: region: description: The AWS region enum: - cn-north-1 - cn-northwest-1 default: cn-north-1 description: The Amazon Cognito Identity endpoint for China (Beijing) and China (Ningxia) - url: https://cognito-identity.{region}.amazonaws.com.cn variables: region: description: The AWS region enum: - cn-north-1 - cn-northwest-1 default: cn-north-1 description: The Amazon Cognito Identity endpoint for China (Beijing) and China (Ningxia) security: - hmac: [] tags: - name: '#X Amz Target=AWSCognitoIdentityProviderService.GetUser' paths: /#X-Amz-Target=AWSCognitoIdentityProviderService.GetUser: parameters: - $ref: '#/components/parameters/X-Amz-Content-Sha256' - $ref: '#/components/parameters/X-Amz-Date' - $ref: '#/components/parameters/X-Amz-Algorithm' - $ref: '#/components/parameters/X-Amz-Credential' - $ref: '#/components/parameters/X-Amz-Security-Token' - $ref: '#/components/parameters/X-Amz-Signature' - $ref: '#/components/parameters/X-Amz-SignedHeaders' post: operationId: GetUser description: Gets the user attributes and metadata for a user. responses: '200': description: Success content: application/json: schema: $ref: '#/components/schemas/GetUserResponse' examples: GetUser200Example: summary: Default GetUser 200 response x-microcks-default: true value: Username: my-user-pool UserAttributes: example-value MFAOptions: example-value PreferredMfaSetting: example-value UserMFASettingList: example-value '480': description: ResourceNotFoundException content: application/json: schema: $ref: '#/components/schemas/ResourceNotFoundException' examples: GetUser480Example: summary: Default GetUser 480 response x-microcks-default: true value: example '481': description: InvalidParameterException content: application/json: schema: $ref: '#/components/schemas/InvalidParameterException' examples: GetUser481Example: summary: Default GetUser 481 response x-microcks-default: true value: example '482': description: NotAuthorizedException content: application/json: schema: $ref: '#/components/schemas/NotAuthorizedException' examples: GetUser482Example: summary: Default GetUser 482 response x-microcks-default: true value: example '483': description: TooManyRequestsException content: application/json: schema: $ref: '#/components/schemas/TooManyRequestsException' examples: GetUser483Example: summary: Default GetUser 483 response x-microcks-default: true value: example '484': description: PasswordResetRequiredException content: application/json: schema: $ref: '#/components/schemas/PasswordResetRequiredException' examples: GetUser484Example: summary: Default GetUser 484 response x-microcks-default: true value: example '485': description: UserNotFoundException content: application/json: schema: $ref: '#/components/schemas/UserNotFoundException' examples: GetUser485Example: summary: Default GetUser 485 response x-microcks-default: true value: example '486': description: UserNotConfirmedException content: application/json: schema: $ref: '#/components/schemas/UserNotConfirmedException' examples: GetUser486Example: summary: Default GetUser 486 response x-microcks-default: true value: example '487': description: InternalErrorException content: application/json: schema: $ref: '#/components/schemas/InternalErrorException' examples: GetUser487Example: summary: Default GetUser 487 response x-microcks-default: true value: example '488': description: ForbiddenException content: application/json: schema: $ref: '#/components/schemas/ForbiddenException' examples: GetUser488Example: summary: Default GetUser 488 response x-microcks-default: true value: example requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/GetUserRequest' examples: GetUserRequestExample: summary: Default GetUser request x-microcks-default: true value: AccessToken: eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9... parameters: - name: X-Amz-Target in: header required: true schema: type: string enum: - AWSCognitoIdentityProviderService.GetUser summary: Amazon Cognito Get User x-microcks-operation: delay: 0 dispatcher: FALLBACK tags: - '#X Amz Target=AWSCognitoIdentityProviderService.GetUser' components: schemas: ResourceNotFoundException: {} AttributeType: type: object required: - Name properties: Name: allOf: - $ref: '#/components/schemas/AttributeNameType' - description: The name of the attribute. Value: allOf: - $ref: '#/components/schemas/AttributeValueType' - description: The value of the attribute. description: Specifies whether the attribute is standard or custom. AttributeNameType: type: string pattern: '[\p{L}\p{M}\p{S}\p{N}\p{P}]+' minLength: 1 maxLength: 32 UserNotFoundException: {} AttributeListType: type: array items: $ref: '#/components/schemas/AttributeType' DeliveryMediumType: type: string enum: - SMS - EMAIL UserNotConfirmedException: {} InvalidParameterException: {} GetUserRequest: type: object required: - AccessToken title: GetUserRequest properties: AccessToken: allOf: - $ref: '#/components/schemas/TokenModelType' - description: A non-expired access token for the user whose information you want to query. description: Represents the request to get information about the user. TooManyRequestsException: {} InternalErrorException: {} MFAOptionListType: type: array items: $ref: '#/components/schemas/MFAOptionType' GetUserResponse: type: object required: - Username - UserAttributes properties: Username: allOf: - $ref: '#/components/schemas/UsernameType' - description: The user name of the user you want to retrieve from the get user request. UserAttributes: allOf: - $ref: '#/components/schemas/AttributeListType' - description:

An array of name-value pairs representing user attributes.

For custom attributes, you must prepend the custom: prefix to the attribute name.

MFAOptions: allOf: - $ref: '#/components/schemas/MFAOptionListType' - description: ' This response parameter is no longer supported. It provides information only about SMS MFA configurations. It doesn''t provide information about time-based one-time password (TOTP) software token MFA configurations. To look up information about either type of MFA configuration, use UserMFASettingList instead.' PreferredMfaSetting: allOf: - $ref: '#/components/schemas/StringType' - description: The user's preferred MFA setting. UserMFASettingList: allOf: - $ref: '#/components/schemas/UserMFASettingListType' - description: The MFA options that are activated for the user. The possible values in this list are SMS_MFA and SOFTWARE_TOKEN_MFA. description: Represents the response from the server from the request to get information about the user. StringType: type: string NotAuthorizedException: {} PasswordResetRequiredException: {} TokenModelType: type: string pattern: '[A-Za-z0-9-_=.]+' format: password UserMFASettingListType: type: array items: $ref: '#/components/schemas/StringType' UsernameType: type: string pattern: '[\p{L}\p{M}\p{S}\p{N}\p{P}]+' minLength: 1 maxLength: 128 format: password ForbiddenException: {} AttributeValueType: type: string maxLength: 2048 format: password MFAOptionType: type: object properties: DeliveryMedium: allOf: - $ref: '#/components/schemas/DeliveryMediumType' - description: The delivery medium to send the MFA code. You can use this parameter to set only the SMS delivery medium value. AttributeName: allOf: - $ref: '#/components/schemas/AttributeNameType' - description: The attribute name of the MFA option type. The only valid value is phone_number. description: ' This data type is no longer supported. Applies only to SMS multi-factor authentication (MFA) configurations. Does not apply to time-based one-time password (TOTP) software token MFA configurations.' parameters: X-Amz-Credential: name: X-Amz-Credential in: header schema: type: string required: false X-Amz-Date: name: X-Amz-Date in: header schema: type: string required: false X-Amz-Signature: name: X-Amz-Signature in: header schema: type: string required: false X-Amz-Algorithm: name: X-Amz-Algorithm in: header schema: type: string required: false X-Amz-Security-Token: name: X-Amz-Security-Token in: header schema: type: string required: false X-Amz-SignedHeaders: name: X-Amz-SignedHeaders in: header schema: type: string required: false X-Amz-Content-Sha256: name: X-Amz-Content-Sha256 in: header schema: type: string required: false securitySchemes: hmac: type: apiKey name: Authorization in: header description: Amazon Signature authorization v4 x-amazon-apigateway-authtype: awsSigv4 externalDocs: description: Amazon Web Services documentation url: https://docs.aws.amazon.com/cognito-identity/ x-hasEquivalentPaths: true