Integration with AWS Cognito


We are using AWS to host our application, we’ve added our services to the AWS API Gateway and we were thinking of using AWS Cognito Pools for authenticating the users.
So my questions are:

  1. Is it possible to integrate the application authorization with AWS Cognito?
  2. If the first step is possible, will this be considered as custom provider?

We’ll be glad to know your suggestions.

1 Like

Unfortunately, we don’t have experience with AWS Cognito. At the first glance, you can implement your own CubaAuthProvider ([url=][/url]) and use it the same way we implement LDAP authentication: [url=][/url] See com.haulmont.cuba.web.auth.LdapAuthProvider as an example of a simple authentication with user/password using an external system.


is that still the way to go when it comes to AWS cognito? I have seen a couple of improvements have been made on the CUBA side but also on the Cognito side.

It seems multiple new mechanisms in CUBA have been established:

Also there is the new SAML addon as well as the already established LDAP addon.

With so many options what would be the preferred way of solving one of the following integration scenarios with Cognito:

  • Regular username & password authentication
  • OAuth webflow (see guide)
  • SSO

Perhaps someone has some insights on how a cognito based authentication backend could be implemented.