Class: AWS.CognitoIdentityServiceProvider
- Inherits:
-
AWS.Service
- Object
- AWS.Service
- AWS.CognitoIdentityServiceProvider
- Identifier:
- cognitoidentityserviceprovider
- API Version:
- 2016-04-18
- Defined in:
- (unknown)
Overview
Constructs a service interface object. Each API operation is exposed as a function on service.
Service Description
With the Amazon Cognito user pools API, you can configure user pools and authenticate users. To authenticate users from third-party identity providers (IdPs) in this API, you can link IdP users to native user profiles. Learn more about the authentication and authorization of federated users at Adding user pool sign-in through a third party and in the User pool federation endpoints and hosted UI reference.
This API reference provides detailed information about API operations and object types in Amazon Cognito.
Along with resource management operations, the Amazon Cognito user pools API includes classes of operations and authorization models for client-side and server-side authentication of users. You can interact with operations in the Amazon Cognito user pools API as any of the following subjects.
-
An administrator who wants to configure user pools, app clients, users, groups, or other user pool functions.
-
A server-side app, like a web application, that wants to use its Amazon Web Services privileges to manage, authenticate, or authorize a user.
-
A client-side app, like a mobile app, that wants to make unauthenticated requests to manage, authenticate, or authorize a user.
For more information, see Using the Amazon Cognito user pools API and user pool endpoints in the Amazon Cognito Developer Guide.
With your Amazon Web Services SDK, you can build the logic to support operational flows in every use case for this API. You can also make direct REST API requests to Amazon Cognito user pools service endpoints. The following links can get you started with the CognitoIdentityProvider client in other supported Amazon Web Services SDKs.
To get started with an Amazon Web Services SDK, see Tools to Build on Amazon Web Services. For example actions and scenarios, see Code examples for Amazon Cognito Identity Provider using Amazon Web Services SDKs.
Sending a Request Using CognitoIdentityServiceProvider
var cognitoidentityserviceprovider = new AWS.CognitoIdentityServiceProvider();
cognitoidentityserviceprovider.adminForgetDevice(params, function (err, data) {
if (err) console.log(err, err.stack); // an error occurred
else console.log(data); // successful response
});
Locking the API Version
In order to ensure that the CognitoIdentityServiceProvider object uses this specific API, you can
construct the object by passing the apiVersion option to the constructor:
var cognitoidentityserviceprovider = new AWS.CognitoIdentityServiceProvider({apiVersion: '2016-04-18'});
You can also set the API version globally in AWS.config.apiVersions using
the cognitoidentityserviceprovider service identifier:
AWS.config.apiVersions = {
cognitoidentityserviceprovider: '2016-04-18',
// other service API versions
};
var cognitoidentityserviceprovider = new AWS.CognitoIdentityServiceProvider();
Constructor Summary collapse
-
new AWS.CognitoIdentityServiceProvider(options = {}) ⇒ Object
constructor
Constructs a service object.
Property Summary collapse
-
endpoint ⇒ AWS.Endpoint
readwrite
An Endpoint object representing the endpoint URL for service requests.
Properties inherited from AWS.Service
Method Summary collapse
-
addCustomAttributes(params = {}, callback) ⇒ AWS.Request
Adds additional user attributes to the user pool schema.
Note: Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation.- adminAddUserToGroup(params = {}, callback) ⇒ AWS.Request
Adds a user to a group.
- adminConfirmSignUp(params = {}, callback) ⇒ AWS.Request
This IAM-authenticated API operation confirms user sign-up as an administrator.
- adminCreateUser(params = {}, callback) ⇒ AWS.Request
Creates a new user in the specified user pool.
If
MessageActionisn't set, the default is to send a welcome message via email or phone (SMS).Note: This action might generate an SMS text message.- adminDeleteUser(params = {}, callback) ⇒ AWS.Request
Deletes a user as an administrator.
- adminDeleteUserAttributes(params = {}, callback) ⇒ AWS.Request
Deletes the user attributes in a user pool as an administrator.
- adminDisableProviderForUser(params = {}, callback) ⇒ AWS.Request
Prevents the user from signing in with the specified external (SAML or social) identity provider (IdP).
- adminDisableUser(params = {}, callback) ⇒ AWS.Request
Deactivates a user and revokes all access tokens for the user.
- adminEnableUser(params = {}, callback) ⇒ AWS.Request
Enables the specified user as an administrator.
- adminForgetDevice(params = {}, callback) ⇒ AWS.Request
Forgets the device, as an administrator.
Note: Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation.- adminGetDevice(params = {}, callback) ⇒ AWS.Request
Gets the device, as an administrator.
Note: Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation.- adminGetUser(params = {}, callback) ⇒ AWS.Request
Gets the specified user by user name in a user pool as an administrator.
- adminInitiateAuth(params = {}, callback) ⇒ AWS.Request
Initiates the authentication flow, as an administrator.
Note: This action might generate an SMS text message.- adminLinkProviderForUser(params = {}, callback) ⇒ AWS.Request
Links an existing user account in a user pool (
DestinationUser) to an identity from an external IdP (SourceUser) based on a specified attribute name and value from the external IdP.- adminListDevices(params = {}, callback) ⇒ AWS.Request
Lists devices, as an administrator.
Note: Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation.- adminListGroupsForUser(params = {}, callback) ⇒ AWS.Request
Lists the groups that a user belongs to.
Note: Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation.- adminListUserAuthEvents(params = {}, callback) ⇒ AWS.Request
A history of user activity and any risks detected as part of Amazon Cognito advanced security.
Note: Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation.- adminRemoveUserFromGroup(params = {}, callback) ⇒ AWS.Request
Removes the specified user from the specified group.
Note: Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation.- adminResetUserPassword(params = {}, callback) ⇒ AWS.Request
Resets the specified user's password in a user pool as an administrator.
- adminRespondToAuthChallenge(params = {}, callback) ⇒ AWS.Request
Some API operations in a user pool generate a challenge, like a prompt for an MFA code, for device authentication that bypasses MFA, or for a custom authentication challenge.
- adminSetUserMFAPreference(params = {}, callback) ⇒ AWS.Request
The user's multi-factor authentication (MFA) preference, including which MFA options are activated, and if any are preferred.
- adminSetUserPassword(params = {}, callback) ⇒ AWS.Request
Sets the specified user's password in a user pool as an administrator.
- adminSetUserSettings(params = {}, callback) ⇒ AWS.Request
This action is no longer supported. You can use it to configure only SMS MFA.
- adminUpdateAuthEventFeedback(params = {}, callback) ⇒ AWS.Request
Provides feedback for an authentication event indicating if it was from a valid user.
- adminUpdateDeviceStatus(params = {}, callback) ⇒ AWS.Request
Updates the device status as an administrator.
Note: Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation.- adminUpdateUserAttributes(params = {}, callback) ⇒ AWS.Request
Note: This action might generate an SMS text message.- adminUserGlobalSignOut(params = {}, callback) ⇒ AWS.Request
Invalidates the identity, access, and refresh tokens that Amazon Cognito issued to a user.
- associateSoftwareToken(params = {}, callback) ⇒ AWS.Request
Begins setup of time-based one-time password (TOTP) multi-factor authentication (MFA) for a user, with a unique private key that Amazon Cognito generates and returns in the API response.
- changePassword(params = {}, callback) ⇒ AWS.Request
Changes the password for a specified user in a user pool.
Authorize this action with a signed-in user's access token.
- confirmDevice(params = {}, callback) ⇒ AWS.Request
Confirms tracking of the device.
- confirmForgotPassword(params = {}, callback) ⇒ AWS.Request
Allows a user to enter a confirmation code to reset a forgotten password.
Note: Amazon Cognito doesn't evaluate Identity and Access Management (IAM) policies in requests for this API operation.- confirmSignUp(params = {}, callback) ⇒ AWS.Request
This public API operation provides a code that Amazon Cognito sent to your user when they signed up in your user pool via the SignUp API operation.
- createGroup(params = {}, callback) ⇒ AWS.Request
Creates a new group in the specified user pool.
Note: Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation.- createIdentityProvider(params = {}, callback) ⇒ AWS.Request
Adds a configuration and trust relationship between a third-party identity provider (IdP) and a user pool.
Note: Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation.- createResourceServer(params = {}, callback) ⇒ AWS.Request
Creates a new OAuth2.0 resource server and defines custom scopes within it.
Note: Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation.- createUserImportJob(params = {}, callback) ⇒ AWS.Request
Creates a user import job.
Note: Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation.- createUserPool(params = {}, callback) ⇒ AWS.Request
Note: This action might generate an SMS text message.- createUserPoolClient(params = {}, callback) ⇒ AWS.Request
Creates the user pool client.
When you create a new user pool client, token revocation is automatically activated.
- createUserPoolDomain(params = {}, callback) ⇒ AWS.Request
Creates a new domain for a user pool.
Note: Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation.- deleteGroup(params = {}, callback) ⇒ AWS.Request
Deletes a group.
Calling this action requires developer credentials.
.- deleteIdentityProvider(params = {}, callback) ⇒ AWS.Request
Deletes an IdP for a user pool.
.
- deleteResourceServer(params = {}, callback) ⇒ AWS.Request
Deletes a resource server.
.
- deleteUser(params = {}, callback) ⇒ AWS.Request
Allows a user to delete their own user profile.
Authorize this action with a signed-in user's access token.
- deleteUserAttributes(params = {}, callback) ⇒ AWS.Request
Deletes the attributes for a user.
Authorize this action with a signed-in user's access token.
- deleteUserPool(params = {}, callback) ⇒ AWS.Request
Deletes the specified Amazon Cognito user pool.
.
- deleteUserPoolClient(params = {}, callback) ⇒ AWS.Request
Allows the developer to delete the user pool client.
.
- deleteUserPoolDomain(params = {}, callback) ⇒ AWS.Request
Deletes a domain for a user pool.
.
- describeIdentityProvider(params = {}, callback) ⇒ AWS.Request
Gets information about a specific IdP.
.
- describeResourceServer(params = {}, callback) ⇒ AWS.Request
Describes a resource server.
.
- describeRiskConfiguration(params = {}, callback) ⇒ AWS.Request
Describes the risk configuration.
.
- describeUserImportJob(params = {}, callback) ⇒ AWS.Request
Describes the user import job.
.
- describeUserPool(params = {}, callback) ⇒ AWS.Request
Returns the configuration information and metadata of the specified user pool.
Note: Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation.- describeUserPoolClient(params = {}, callback) ⇒ AWS.Request
Client method for returning the configuration information and metadata of the specified user pool app client.
Note: Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation.- describeUserPoolDomain(params = {}, callback) ⇒ AWS.Request
Gets information about a domain.
.
- forgetDevice(params = {}, callback) ⇒ AWS.Request
Forgets the specified device.
- forgotPassword(params = {}, callback) ⇒ AWS.Request
Calling this API causes a message to be sent to the end user with a confirmation code that is required to change the user's password.
- getCSVHeader(params = {}, callback) ⇒ AWS.Request
Gets the header information for the comma-separated value (CSV) file to be used as input for the user import job.
.
- getDevice(params = {}, callback) ⇒ AWS.Request
Gets the device.
- getGroup(params = {}, callback) ⇒ AWS.Request
Gets a group.
Calling this action requires developer credentials.
.- getIdentityProviderByIdentifier(params = {}, callback) ⇒ AWS.Request
Gets the specified IdP.
.
- getLogDeliveryConfiguration(params = {}, callback) ⇒ AWS.Request
Gets the logging configuration of a user pool.
.
- getSigningCertificate(params = {}, callback) ⇒ AWS.Request
This method takes a user pool ID, and returns the signing certificate.
- getUICustomization(params = {}, callback) ⇒ AWS.Request
Gets the user interface (UI) Customization information for a particular app client's app UI, if any such information exists for the client.
- getUser(params = {}, callback) ⇒ AWS.Request
Gets the user attributes and metadata for a user.
Authorize this action with a signed-in user's access token.
- getUserAttributeVerificationCode(params = {}, callback) ⇒ AWS.Request
Generates a user attribute verification code for the specified attribute name.
- getUserPoolMfaConfig(params = {}, callback) ⇒ AWS.Request
Gets the user pool multi-factor authentication (MFA) configuration.
.
- globalSignOut(params = {}, callback) ⇒ AWS.Request
Invalidates the identity, access, and refresh tokens that Amazon Cognito issued to a user.
- initiateAuth(params = {}, callback) ⇒ AWS.Request
Initiates sign-in for a user in the Amazon Cognito user directory.
- listDevices(params = {}, callback) ⇒ AWS.Request
Lists the sign-in devices that Amazon Cognito has registered to the current user.
- listGroups(params = {}, callback) ⇒ AWS.Request
Lists the groups associated with a user pool.
Note: Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation.- listIdentityProviders(params = {}, callback) ⇒ AWS.Request
Lists information about all IdPs for a user pool.
Note: Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation.- listResourceServers(params = {}, callback) ⇒ AWS.Request
Lists the resource servers for a user pool.
Note: Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation.- listTagsForResource(params = {}, callback) ⇒ AWS.Request
Lists the tags that are assigned to an Amazon Cognito user pool.
A tag is a label that you can apply to user pools to categorize and manage them in different ways, such as by purpose, owner, environment, or other criteria.
You can use this action up to 10 times per second, per account.
.- listUserImportJobs(params = {}, callback) ⇒ AWS.Request
Lists user import jobs for a user pool.
Note: Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation.- listUserPoolClients(params = {}, callback) ⇒ AWS.Request
Lists the clients that have been created for the specified user pool.
Note: Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation.- listUserPools(params = {}, callback) ⇒ AWS.Request
Lists the user pools associated with an Amazon Web Services account.
Note: Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation.- listUsers(params = {}, callback) ⇒ AWS.Request
Lists users and their basic details in a user pool.
Note: Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation.- listUsersInGroup(params = {}, callback) ⇒ AWS.Request
Lists the users in the specified group.
Note: Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation.- resendConfirmationCode(params = {}, callback) ⇒ AWS.Request
Resends the confirmation (for confirmation of registration) to a specific user in the user pool.
Note: Amazon Cognito doesn't evaluate Identity and Access Management (IAM) policies in requests for this API operation.- respondToAuthChallenge(params = {}, callback) ⇒ AWS.Request
Some API operations in a user pool generate a challenge, like a prompt for an MFA code, for device authentication that bypasses MFA, or for a custom authentication challenge.
- revokeToken(params = {}, callback) ⇒ AWS.Request
Revokes all of the access tokens generated by, and at the same time as, the specified refresh token.
- setLogDeliveryConfiguration(params = {}, callback) ⇒ AWS.Request
Sets up or modifies the logging configuration of a user pool.
- setRiskConfiguration(params = {}, callback) ⇒ AWS.Request
Configures actions on detected risks.
- setUICustomization(params = {}, callback) ⇒ AWS.Request
Sets the user interface (UI) customization information for a user pool's built-in app UI.
You can specify app UI customization settings for a single client (with a specific
clientId) or for all clients (by setting theclientIdtoALL).- setUserMFAPreference(params = {}, callback) ⇒ AWS.Request
Set the user's multi-factor authentication (MFA) method preference, including which MFA factors are activated and if any are preferred.
- setUserPoolMfaConfig(params = {}, callback) ⇒ AWS.Request
Sets the user pool multi-factor authentication (MFA) configuration.
Note: This action might generate an SMS text message.- setUserSettings(params = {}, callback) ⇒ AWS.Request
This action is no longer supported. You can use it to configure only SMS MFA.
- signUp(params = {}, callback) ⇒ AWS.Request
Registers the user in the specified user pool and creates a user name, password, and user attributes.
Note: Amazon Cognito doesn't evaluate Identity and Access Management (IAM) policies in requests for this API operation.- startUserImportJob(params = {}, callback) ⇒ AWS.Request
Starts the user import.
.
- stopUserImportJob(params = {}, callback) ⇒ AWS.Request
Stops the user import job.
.
- tagResource(params = {}, callback) ⇒ AWS.Request
Assigns a set of tags to an Amazon Cognito user pool.
- untagResource(params = {}, callback) ⇒ AWS.Request
Removes the specified tags from an Amazon Cognito user pool.
- updateAuthEventFeedback(params = {}, callback) ⇒ AWS.Request
Provides the feedback for an authentication event, whether it was from a valid user or not.
- updateDeviceStatus(params = {}, callback) ⇒ AWS.Request
Updates the device status.
- updateGroup(params = {}, callback) ⇒ AWS.Request
Updates the specified group with the specified attributes.
Note: Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation.- updateIdentityProvider(params = {}, callback) ⇒ AWS.Request
Updates IdP information for a user pool.
Note: Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation.- updateResourceServer(params = {}, callback) ⇒ AWS.Request
Updates the name and scopes of resource server.
- updateUserAttributes(params = {}, callback) ⇒ AWS.Request
With this operation, your users can update one or more of their attributes with their own credentials.
- updateUserPool(params = {}, callback) ⇒ AWS.Request
Note: This action might generate an SMS text message.- updateUserPoolClient(params = {}, callback) ⇒ AWS.Request
Updates the specified user pool app client with the specified attributes.
- updateUserPoolDomain(params = {}, callback) ⇒ AWS.Request
Updates the Secure Sockets Layer (SSL) certificate for the custom domain for your user pool.
You can use this operation to provide the Amazon Resource Name (ARN) of a new certificate to Amazon Cognito.
- verifySoftwareToken(params = {}, callback) ⇒ AWS.Request
Use this API to register a user's entered time-based one-time password (TOTP) code and mark the user's software token MFA status as "verified" if successful.
- verifyUserAttribute(params = {}, callback) ⇒ AWS.Request
Verifies the specified user attributes in the user pool.
If your user pool requires verification before Amazon Cognito updates the attribute value, VerifyUserAttribute updates the affected attribute to its pending value.
Methods inherited from AWS.Service
makeRequest, makeUnauthenticatedRequest, waitFor, setupRequestListeners, defineService
Constructor Details
new AWS.CognitoIdentityServiceProvider(options = {}) ⇒ Object
Constructs a service object. This object has one method for each API operation.
Property Details
Method Details
addCustomAttributes(params = {}, callback) ⇒ AWS.Request
Adds additional user attributes to the user pool schema.
Note: Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.Learn more
- adminAddUserToGroup(params = {}, callback) ⇒ AWS.Request