openapi: 3.0.0
info:
version: 2014-06-30
x-release: v4
title: 'Amazon Cognito Identity #X Amz Target=AWSCognitoIdentityProviderService.AddCustomAttributes #X Amz Target=AWSCognitoIdentityProviderService.AddCustomAttributes #X Amz Target=AWSCognitoIdentityService.GetCredentialsForIdentity API'
description:
Amazon Cognito Federated Identities is a web service that delivers scoped temporary credentials to mobile devices and other untrusted environments. It uniquely identifies a device and supplies the user with a consistent identity over the lifetime of an application.
Using Amazon Cognito Federated Identities, you can enable authentication with one or more third-party identity providers (Facebook, Google, or Login with Amazon) or an Amazon Cognito user pool, and you can also choose to support unauthenticated access from your app. Cognito delivers a unique identifier for each user and acts as an OpenID token provider trusted by AWS Security Token Service (STS) to access temporary, limited-privilege AWS credentials.
For a description of the authentication flow from the Amazon Cognito Developer Guide see Authentication Flow.
For more information see Amazon Cognito Federated Identities.
x-logo: url: https://api.apis.guru/v2/cache/logo/https_twitter.com_awscloud_profile_image.png backgroundColor: '#FFFFFF' termsOfService: https://aws.amazon.com/service-terms/ contact: name: Mike Ralphson email: mike.ralphson@gmail.com url: https://github.com/mermade/aws2openapi x-twitter: PermittedSoc license: name: Apache 2.0 License url: http://www.apache.org/licenses/ x-providerName: amazonaws.com x-serviceName: cognito-identity x-origin: - contentType: application/json url: https://raw.githubusercontent.com/aws/aws-sdk-js/master/apis/cognito-identity-2014-06-30.normal.json converter: url: https://github.com/mermade/aws2openapi version: 1.0.0 x-apisguru-driver: external x-apiClientRegistration: url: https://portal.aws.amazon.com/gp/aws/developer/registration/index.html?nc2=h_ct x-apisguru-categories: - cloud x-preferred: true servers: - url: http://cognito-identity.{region}.amazonaws.com variables: region: description: The AWS region enum: - us-east-1 - us-east-2 - us-west-1 - us-west-2 - us-gov-west-1 - us-gov-east-1 - ca-central-1 - eu-north-1 - eu-west-1 - eu-west-2 - eu-west-3 - eu-central-1 - eu-south-1 - af-south-1 - ap-northeast-1 - ap-northeast-2 - ap-northeast-3 - ap-southeast-1 - ap-southeast-2 - ap-east-1 - ap-south-1 - sa-east-1 - me-south-1 default: us-east-1 description: The Amazon Cognito Identity multi-region endpoint - url: https://cognito-identity.{region}.amazonaws.com variables: region: description: The AWS region enum: - us-east-1 - us-east-2 - us-west-1 - us-west-2 - us-gov-west-1 - us-gov-east-1 - ca-central-1 - eu-north-1 - eu-west-1 - eu-west-2 - eu-west-3 - eu-central-1 - eu-south-1 - af-south-1 - ap-northeast-1 - ap-northeast-2 - ap-northeast-3 - ap-southeast-1 - ap-southeast-2 - ap-east-1 - ap-south-1 - sa-east-1 - me-south-1 default: us-east-1 description: The Amazon Cognito Identity multi-region endpoint - url: http://cognito-identity.{region}.amazonaws.com.cn variables: region: description: The AWS region enum: - cn-north-1 - cn-northwest-1 default: cn-north-1 description: The Amazon Cognito Identity endpoint for China (Beijing) and China (Ningxia) - url: https://cognito-identity.{region}.amazonaws.com.cn variables: region: description: The AWS region enum: - cn-north-1 - cn-northwest-1 default: cn-north-1 description: The Amazon Cognito Identity endpoint for China (Beijing) and China (Ningxia) security: - hmac: [] tags: - name: '#X Amz Target=AWSCognitoIdentityService.GetCredentialsForIdentity' paths: /#X-Amz-Target=AWSCognitoIdentityService.GetCredentialsForIdentity: parameters: - $ref: '#/components/parameters/X-Amz-Content-Sha256' - $ref: '#/components/parameters/X-Amz-Date' - $ref: '#/components/parameters/X-Amz-Algorithm' - $ref: '#/components/parameters/X-Amz-Credential' - $ref: '#/components/parameters/X-Amz-Security-Token' - $ref: '#/components/parameters/X-Amz-Signature' - $ref: '#/components/parameters/X-Amz-SignedHeaders' post: operationId: GetCredentialsForIdentity description:Returns credentials for the provided identity ID. Any provided logins will be validated against supported login providers. If the token is for cognito-identity.amazonaws.com, it will be passed through to AWS Security Token Service with the appropriate role for the token.
This is a public API. You do not need any credentials to call this API.
responses: '200': description: Success content: application/json: schema: $ref: '#/components/schemas/GetCredentialsForIdentityResponse' examples: GetCredentialsForIdentity200Example: summary: Default GetCredentialsForIdentity 200 response x-microcks-default: true value: IdentityId: us-east-1_AbCdEfGhI Credentials: example-value '480': description: InvalidParameterException content: application/json: schema: $ref: '#/components/schemas/InvalidParameterException' examples: GetCredentialsForIdentity480Example: summary: Default GetCredentialsForIdentity 480 response x-microcks-default: true value: example '481': description: ResourceNotFoundException content: application/json: schema: $ref: '#/components/schemas/ResourceNotFoundException' examples: GetCredentialsForIdentity481Example: summary: Default GetCredentialsForIdentity 481 response x-microcks-default: true value: example '482': description: NotAuthorizedException content: application/json: schema: $ref: '#/components/schemas/NotAuthorizedException' examples: GetCredentialsForIdentity482Example: summary: Default GetCredentialsForIdentity 482 response x-microcks-default: true value: example '483': description: ResourceConflictException content: application/json: schema: $ref: '#/components/schemas/ResourceConflictException' examples: GetCredentialsForIdentity483Example: summary: Default GetCredentialsForIdentity 483 response x-microcks-default: true value: example '484': description: TooManyRequestsException content: application/json: schema: $ref: '#/components/schemas/TooManyRequestsException' examples: GetCredentialsForIdentity484Example: summary: Default GetCredentialsForIdentity 484 response x-microcks-default: true value: example '485': description: InvalidIdentityPoolConfigurationException content: application/json: schema: $ref: '#/components/schemas/InvalidIdentityPoolConfigurationException' examples: GetCredentialsForIdentity485Example: summary: Default GetCredentialsForIdentity 485 response x-microcks-default: true value: example '486': description: InternalErrorException content: application/json: schema: $ref: '#/components/schemas/InternalErrorException' examples: GetCredentialsForIdentity486Example: summary: Default GetCredentialsForIdentity 486 response x-microcks-default: true value: example '487': description: ExternalServiceException content: application/json: schema: $ref: '#/components/schemas/ExternalServiceException' examples: GetCredentialsForIdentity487Example: summary: Default GetCredentialsForIdentity 487 response x-microcks-default: true value: example requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/GetCredentialsForIdentityInput' examples: GetCredentialsForIdentityRequestExample: summary: Default GetCredentialsForIdentity request x-microcks-default: true value: IdentityId: us-east-1_AbCdEfGhI Logins: example-value CustomRoleArn: arn:aws:cognito-idp:us-east-1:123456789:userpool/us-east-1_AbCdEfGhI parameters: - name: X-Amz-Target in: header required: true schema: type: string enum: - AWSCognitoIdentityService.GetCredentialsForIdentity summary: Amazon Cognito Get Credentials for Identity x-microcks-operation: delay: 0 dispatcher: FALLBACK tags: - '#X Amz Target=AWSCognitoIdentityService.GetCredentialsForIdentity' components: schemas: ResourceNotFoundException: {} Credentials: type: object properties: AccessKeyId: allOf: - $ref: '#/components/schemas/AccessKeyString' - description: The Access Key portion of the credentials. SecretKey: allOf: - $ref: '#/components/schemas/SecretKeyString' - description: The Secret Access Key portion of the credentials SessionToken: allOf: - $ref: '#/components/schemas/SessionTokenString' - description: The Session Token portion of the credentials Expiration: allOf: - $ref: '#/components/schemas/DateType' - description: The date at which these credentials will expire. description: Credentials for the provided identity ID. IdentityId: type: string pattern: '[\w-]+:[0-9a-f-]+' minLength: 1 maxLength: 55 ARNString: type: string minLength: 20 maxLength: 2048 DateType: type: string format: date-time InvalidParameterException: {} LoginsMap: type: object maxProperties: 10 additionalProperties: $ref: '#/components/schemas/IdentityProviderToken' TooManyRequestsException: {} InternalErrorException: {} SecretKeyString: type: string NotAuthorizedException: {} IdentityProviderToken: type: string minLength: 1 maxLength: 50000 AccessKeyString: type: string GetCredentialsForIdentityInput: type: object required: - IdentityId title: GetCredentialsForIdentityInput properties: IdentityId: allOf: - $ref: '#/components/schemas/IdentityId' - description: A unique identifier in the format REGION:GUID. Logins: allOf: - $ref: '#/components/schemas/LoginsMap' - description: 'A set of optional name-value pairs that map provider names to provider tokens. The name-value pair will follow the syntax "provider_name": "provider_user_identifier".
Logins should not be specified when trying to get credentials for an unauthenticated identity.
The Logins parameter is required when using identities associated with external identity providers such as Facebook. For examples of Logins maps, see the code examples in the External Identity Providers section of the Amazon Cognito Developer Guide.
GetCredentialsForIdentity action.
SessionTokenString:
type: string
GetCredentialsForIdentityResponse:
type: object
properties:
IdentityId:
allOf:
- $ref: '#/components/schemas/IdentityId'
- description: A unique identifier in the format REGION:GUID.
Credentials:
allOf:
- $ref: '#/components/schemas/Credentials'
- description: Credentials for the provided identity ID.
description: Returned in response to a successful GetCredentialsForIdentity operation.
ResourceConflictException: {}
InvalidIdentityPoolConfigurationException: {}
ExternalServiceException: {}
parameters:
X-Amz-Credential:
name: X-Amz-Credential
in: header
schema:
type: string
required: false
X-Amz-Date:
name: X-Amz-Date
in: header
schema:
type: string
required: false
X-Amz-Signature:
name: X-Amz-Signature
in: header
schema:
type: string
required: false
X-Amz-Algorithm:
name: X-Amz-Algorithm
in: header
schema:
type: string
required: false
X-Amz-Security-Token:
name: X-Amz-Security-Token
in: header
schema:
type: string
required: false
X-Amz-SignedHeaders:
name: X-Amz-SignedHeaders
in: header
schema:
type: string
required: false
X-Amz-Content-Sha256:
name: X-Amz-Content-Sha256
in: header
schema:
type: string
required: false
securitySchemes:
hmac:
type: apiKey
name: Authorization
in: header
description: Amazon Signature authorization v4
x-amazon-apigateway-authtype: awsSigv4
externalDocs:
description: Amazon Web Services documentation
url: https://docs.aws.amazon.com/cognito-identity/
x-hasEquivalentPaths: true