Skip to main content
See All Integrations

Amazon Cognito

Use an Amazon Cognito User Pool as the identity provider for Pomerium through OpenID Connect.

First-party Pomerium integration guide

Category
Identity Providers

Overview

Amazon Cognito is a managed customer identity service from AWS. A Cognito User Pool can act as an OpenID Connect provider for Pomerium. An Identity Pool is a different AWS feature that exchanges identities for AWS credentials and is not the provider in this pattern.

Using Amazon Cognito as the identity provider gives protected applications one sign-in path. Each application does not need to implement the same external authentication flow. Pomerium can apply route policy from the authenticated identity and request context.

Amazon Cognito sends authenticated identity data toward Pomerium. Pomerium uses that data with route policy. Pomerium then sends only approved application traffic toward the protected service.

How it works

Create an application client in an Amazon Cognito User Pool. Use the authorization code flow. Configure the User Pool issuer and the exact Pomerium callback URL. Do not use an Identity Pool as the OpenID Connect provider.

Configure Pomerium with the exact issuer or provider URL, client ID, and client secret. Use the Pomerium callback URL as an exact redirect URI. Request only the scopes and claims that access policy needs.

Test discovery, signing-key rotation, the authorization code flow, logout, and required claim mappings before production use. Keep provider credentials outside source control.

Example

A team registers Pomerium as an OpenID Connect client in Amazon Cognito. Users sign in through Amazon Cognito. Pomerium validates the identity response and applies route policy before it sends an approved request to a private application.

Considerations

  • Amazon Cognito does not support the generic offline_access scope. Configure Pomerium without that scope.
  • AWS supports original and updated issuer formats. The configured issuer must match the selected User Pool format.
  • Amazon Cognito remains responsible for authentication, user lifecycle, and the identity data that it issues.
  • A standards-based OpenID Connect pattern is not evidence of a vendor-specific connector or partnership.

Sources and official resources

  • Use Microsoft Entra ID as the identity provider for Pomerium through OpenID Connect.

  • Use Keycloak as the identity provider for Pomerium through OpenID Connect.

  • Use authentik as the identity provider for Pomerium through OpenID Connect.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo