openapi: 3.0.0 info: version: 2014-06-30 x-release: v4 title: 'Amazon Cognito Identity #X Amz Target=AWSCognitoIdentityProviderService.AddCustomAttributes #X Amz Target=AWSCognitoIdentityProviderService.AddCustomAttributes #X Amz Target=AWSCognitoIdentityProviderService.GetUserPoolMfaConfig API' description: Amazon Cognito Federated Identities

Amazon Cognito Federated Identities is a web service that delivers scoped temporary credentials to mobile devices and other untrusted environments. It uniquely identifies a device and supplies the user with a consistent identity over the lifetime of an application.

Using Amazon Cognito Federated Identities, you can enable authentication with one or more third-party identity providers (Facebook, Google, or Login with Amazon) or an Amazon Cognito user pool, and you can also choose to support unauthenticated access from your app. Cognito delivers a unique identifier for each user and acts as an OpenID token provider trusted by AWS Security Token Service (STS) to access temporary, limited-privilege AWS credentials.

For a description of the authentication flow from the Amazon Cognito Developer Guide see Authentication Flow.

For more information see Amazon Cognito Federated Identities.

x-logo: url: https://api.apis.guru/v2/cache/logo/https_twitter.com_awscloud_profile_image.png backgroundColor: '#FFFFFF' termsOfService: https://aws.amazon.com/service-terms/ contact: name: Mike Ralphson email: mike.ralphson@gmail.com url: https://github.com/mermade/aws2openapi x-twitter: PermittedSoc license: name: Apache 2.0 License url: http://www.apache.org/licenses/ x-providerName: amazonaws.com x-serviceName: cognito-identity x-origin: - contentType: application/json url: https://raw.githubusercontent.com/aws/aws-sdk-js/master/apis/cognito-identity-2014-06-30.normal.json converter: url: https://github.com/mermade/aws2openapi version: 1.0.0 x-apisguru-driver: external x-apiClientRegistration: url: https://portal.aws.amazon.com/gp/aws/developer/registration/index.html?nc2=h_ct x-apisguru-categories: - cloud x-preferred: true servers: - url: http://cognito-identity.{region}.amazonaws.com variables: region: description: The AWS region enum: - us-east-1 - us-east-2 - us-west-1 - us-west-2 - us-gov-west-1 - us-gov-east-1 - ca-central-1 - eu-north-1 - eu-west-1 - eu-west-2 - eu-west-3 - eu-central-1 - eu-south-1 - af-south-1 - ap-northeast-1 - ap-northeast-2 - ap-northeast-3 - ap-southeast-1 - ap-southeast-2 - ap-east-1 - ap-south-1 - sa-east-1 - me-south-1 default: us-east-1 description: The Amazon Cognito Identity multi-region endpoint - url: https://cognito-identity.{region}.amazonaws.com variables: region: description: The AWS region enum: - us-east-1 - us-east-2 - us-west-1 - us-west-2 - us-gov-west-1 - us-gov-east-1 - ca-central-1 - eu-north-1 - eu-west-1 - eu-west-2 - eu-west-3 - eu-central-1 - eu-south-1 - af-south-1 - ap-northeast-1 - ap-northeast-2 - ap-northeast-3 - ap-southeast-1 - ap-southeast-2 - ap-east-1 - ap-south-1 - sa-east-1 - me-south-1 default: us-east-1 description: The Amazon Cognito Identity multi-region endpoint - url: http://cognito-identity.{region}.amazonaws.com.cn variables: region: description: The AWS region enum: - cn-north-1 - cn-northwest-1 default: cn-north-1 description: The Amazon Cognito Identity endpoint for China (Beijing) and China (Ningxia) - url: https://cognito-identity.{region}.amazonaws.com.cn variables: region: description: The AWS region enum: - cn-north-1 - cn-northwest-1 default: cn-north-1 description: The Amazon Cognito Identity endpoint for China (Beijing) and China (Ningxia) security: - hmac: [] tags: - name: '#X Amz Target=AWSCognitoIdentityProviderService.GetUserPoolMfaConfig' paths: /#X-Amz-Target=AWSCognitoIdentityProviderService.GetUserPoolMfaConfig: parameters: - $ref: '#/components/parameters/X-Amz-Content-Sha256' - $ref: '#/components/parameters/X-Amz-Date' - $ref: '#/components/parameters/X-Amz-Algorithm' - $ref: '#/components/parameters/X-Amz-Credential' - $ref: '#/components/parameters/X-Amz-Security-Token' - $ref: '#/components/parameters/X-Amz-Signature' - $ref: '#/components/parameters/X-Amz-SignedHeaders' post: operationId: GetUserPoolMfaConfig description: Gets the user pool multi-factor authentication (MFA) configuration. responses: '200': description: Success content: application/json: schema: $ref: '#/components/schemas/GetUserPoolMfaConfigResponse' examples: GetUserPoolMfaConfig200Example: summary: Default GetUserPoolMfaConfig 200 response x-microcks-default: true value: SmsMfaConfiguration: example-value SoftwareTokenMfaConfiguration: eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9... MfaConfiguration: example-value '480': description: InvalidParameterException content: application/json: schema: $ref: '#/components/schemas/InvalidParameterException' examples: GetUserPoolMfaConfig480Example: summary: Default GetUserPoolMfaConfig 480 response x-microcks-default: true value: example '481': description: TooManyRequestsException content: application/json: schema: $ref: '#/components/schemas/TooManyRequestsException' examples: GetUserPoolMfaConfig481Example: summary: Default GetUserPoolMfaConfig 481 response x-microcks-default: true value: example '482': description: ResourceNotFoundException content: application/json: schema: $ref: '#/components/schemas/ResourceNotFoundException' examples: GetUserPoolMfaConfig482Example: summary: Default GetUserPoolMfaConfig 482 response x-microcks-default: true value: example '483': description: NotAuthorizedException content: application/json: schema: $ref: '#/components/schemas/NotAuthorizedException' examples: GetUserPoolMfaConfig483Example: summary: Default GetUserPoolMfaConfig 483 response x-microcks-default: true value: example '484': description: InternalErrorException content: application/json: schema: $ref: '#/components/schemas/InternalErrorException' examples: GetUserPoolMfaConfig484Example: summary: Default GetUserPoolMfaConfig 484 response x-microcks-default: true value: example requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/GetUserPoolMfaConfigRequest' examples: GetUserPoolMfaConfigRequestExample: summary: Default GetUserPoolMfaConfig request x-microcks-default: true value: UserPoolId: us-east-1_AbCdEfGhI parameters: - name: X-Amz-Target in: header required: true schema: type: string enum: - AWSCognitoIdentityProviderService.GetUserPoolMfaConfig summary: Amazon Cognito Get User Pool Mfa Config x-microcks-operation: delay: 0 dispatcher: FALLBACK tags: - '#X Amz Target=AWSCognitoIdentityProviderService.GetUserPoolMfaConfig' components: schemas: ResourceNotFoundException: {} UserPoolMfaType: type: string enum: - false - true - OPTIONAL SmsConfigurationType: type: object required: - SnsCallerArn properties: SnsCallerArn: allOf: - $ref: '#/components/schemas/ArnType' - description: 'The Amazon Resource Name (ARN) of the Amazon SNS caller. This is the ARN of the IAM role in your Amazon Web Services account that Amazon Cognito will use to send SMS messages. SMS messages are subject to a spending limit. ' ExternalId: allOf: - $ref: '#/components/schemas/StringType' - description:

The external ID provides additional security for your IAM role. You can use an ExternalId with the IAM role that you use with Amazon SNS to send SMS messages for your user pool. If you provide an ExternalId, your Amazon Cognito user pool includes it in the request to assume your IAM role. You can configure the role trust policy to require that Amazon Cognito, and any principal, provide the ExternalID. If you use the Amazon Cognito Management Console to create a role for SMS multi-factor authentication (MFA), Amazon Cognito creates a role with the required permissions and a trust policy that demonstrates use of the ExternalId.

For more information about the ExternalId of a role, see How to use an external ID when granting access to your Amazon Web Services resources to a third party

SnsRegion: allOf: - $ref: '#/components/schemas/RegionCodeType' - description:

The Amazon Web Services Region to use with Amazon SNS integration. You can choose the same Region as your user pool, or a supported Legacy Amazon SNS alternate Region.

Amazon Cognito resources in the Asia Pacific (Seoul) Amazon Web Services Region must use your Amazon SNS configuration in the Asia Pacific (Tokyo) Region. For more information, see SMS message settings for Amazon Cognito user pools.

description: The SMS configuration type is the settings that your Amazon Cognito user pool must use to send an SMS message from your Amazon Web Services account through Amazon Simple Notification Service. To send SMS messages with Amazon SNS in the Amazon Web Services Region that you want, the Amazon Cognito user pool uses an Identity and Access Management (IAM) role in your Amazon Web Services account. GetUserPoolMfaConfigResponse: type: object properties: SmsMfaConfiguration: allOf: - $ref: '#/components/schemas/SmsMfaConfigType' - description: The SMS text message multi-factor authentication (MFA) configuration. SoftwareTokenMfaConfiguration: allOf: - $ref: '#/components/schemas/SoftwareTokenMfaConfigType' - description: The software token multi-factor authentication (MFA) configuration. MfaConfiguration: allOf: - $ref: '#/components/schemas/UserPoolMfaType' - description:

The multi-factor authentication (MFA) configuration. Valid values include:

SmsVerificationMessageType: type: string pattern: .*\{####\}.* minLength: 6 maxLength: 140 InvalidParameterException: {} SoftwareTokenMfaConfigType: type: object properties: Enabled: allOf: - $ref: '#/components/schemas/BooleanType' - description: Specifies whether software token MFA is activated. description: The type used for enabling software token MFA at the user pool level. RegionCodeType: type: string minLength: 5 maxLength: 32 TooManyRequestsException: {} InternalErrorException: {} StringType: type: string NotAuthorizedException: {} GetUserPoolMfaConfigRequest: type: object required: - UserPoolId title: GetUserPoolMfaConfigRequest properties: UserPoolId: allOf: - $ref: '#/components/schemas/UserPoolIdType' - description: The user pool ID. UserPoolIdType: type: string pattern: '[\w-]+_[0-9a-zA-Z]+' minLength: 1 maxLength: 55 BooleanType: type: boolean ArnType: type: string pattern: arn:[\w+=/,.@-]+:[\w+=/,.@-]+:([\w+=/,.@-]*)?:[0-9]+:[\w+=/,.@-]+(:[\w+=/,.@-]+)?(:[\w+=/,.@-]+)? minLength: 20 maxLength: 2048 SmsMfaConfigType: type: object properties: SmsAuthenticationMessage: allOf: - $ref: '#/components/schemas/SmsVerificationMessageType' - description: The SMS authentication message that will be sent to users with the code they must sign in. The message must contain the ‘{####}’ placeholder, which is replaced with the code. If the message isn't included, and default message will be used. SmsConfiguration: allOf: - $ref: '#/components/schemas/SmsConfigurationType' - description: The SMS configuration with the settings that your Amazon Cognito user pool must use to send an SMS message from your Amazon Web Services account through Amazon Simple Notification Service. To request Amazon SNS in the Amazon Web Services Region that you want, the Amazon Cognito user pool uses an Identity and Access Management (IAM) role that you provide for your Amazon Web Services account. description: The SMS text message multi-factor authentication (MFA) configuration type. parameters: X-Amz-Credential: name: X-Amz-Credential in: header schema: type: string required: false X-Amz-Date: name: X-Amz-Date in: header schema: type: string required: false X-Amz-Signature: name: X-Amz-Signature in: header schema: type: string required: false X-Amz-Algorithm: name: X-Amz-Algorithm in: header schema: type: string required: false X-Amz-Security-Token: name: X-Amz-Security-Token in: header schema: type: string required: false X-Amz-SignedHeaders: name: X-Amz-SignedHeaders in: header schema: type: string required: false X-Amz-Content-Sha256: name: X-Amz-Content-Sha256 in: header schema: type: string required: false securitySchemes: hmac: type: apiKey name: Authorization in: header description: Amazon Signature authorization v4 x-amazon-apigateway-authtype: awsSigv4 externalDocs: description: Amazon Web Services documentation url: https://docs.aws.amazon.com/cognito-identity/ x-hasEquivalentPaths: true