Add Facebook as a social identity provider
Note
Last verified against the provider console: October
2, 2026. Facebook steps use the Meta for
Developers
To let your users sign in with Facebook, you create a Meta app with the Facebook Login use case, then add Facebook as an identity provider (IdP) in your user pool. You must enable managed login first.
Create a Meta app for Facebook Login
To create and configure a Meta app
-
Sign in to Meta for Developers
, choose My Apps, then Create App. -
For the use case, choose Authenticate and request data from users with Facebook Login. Finish creating the app. New apps start in Development mode.
-
From App settings, then Basic, record the App ID and App secret. Set App Domains to your user pool domain host (
<your-prefix>.auth.<region>.amazoncognito.comorauth.example.com), and add the Website platform with your managed login sign-in URL as the Site URL. -
Go to Use cases, choose your Facebook Login use case, then Customize. Confirm the
public_profilepermission (required) and addemail. -
In the use case Settings, set Valid OAuth Redirect URIs to the
/oauth2/idpresponseendpoint of your user pool domain:-
Default Amazon Cognito domain:
https://<your-prefix>.auth.<region>.amazoncognito.com/oauth2/idpresponse -
Custom domain:
https://auth.example.com/oauth2/idpresponse
-
Add Facebook to your user pool
To add Facebook as an IdP in the AWS Management Console
-
In the Amazon Cognito console
, choose your user pool, then Social and external providers, then Add an identity provider, then Facebook. -
Enter the App ID and App secret, and choose a Facebook API version. Choose the latest available version, because each version has a discontinuation date and scopes can vary between versions.
-
For Authorized scopes, enter
public_profile,email, separated by commas. -
Map
emailtoemailandnametoname. -
Choose Add identity provider, and enable Facebook on your app client.
Test Facebook sign-in
While the app is in Development mode, add your own Facebook account as an app role (Administrator, Developer, or Tester). Then open your managed login sign-in page and choose Continue with Facebook.
Checkpoint
Facebook returns through /oauth2/idpresponse to your app with an
authorization code, and a new federated user appears in your user pool with
email and name populated. Then switch the app to
Live mode and confirm a non-role account can sign in. A
non-role account that sees "app not active" or "in development mode" means the app
is still in Development mode or lacks Advanced Access.
Facebook-specific pitfalls
- Development mode and app review
-
A new app is in Development mode and only app-role users (Administrator, Developer, Tester) can sign in. To let the general public sign in, switch the app to Live mode, complete Business Verification, and obtain Advanced Access for
email(and increased access forpublic_profile). First-time testers often hit "app not active" because they test with a non-role account. - No email_verified claim
-
Facebook does not return an
email_verifiedclaim, so there is nothing to map, and Amazon Cognito treats the Facebook email as unverified. Don't assume a verified email from Facebook, and link accounts by email only through deliberate, trusted logic rather than automatically. - Keep scopes small
-
Sign-in completion drops sharply past about four permissions. Keep the request to
public_profileandemail. Amazon Cognito federation is also not compatible with Facebook Limited Login on iOS.