Implement authentication flows
Whether you're implementing managed login or a custom-built application front end with an AWS SDK for authentication, you must configure your app client for the types of authentication that you want to implement. The following information describes setup for authentication flows in your app clients and your application.
- App client supported flows
-
You can configure supported flows for your app clients in the Amazon Cognito console or with the API in an AWS SDK. After you configure your app client to support these flows, you can deploy them in your application.
The following procedure configures available authentication flows for an app client with the Amazon Cognito console.
To configure an app client for authentication flows (console)
-
Sign in to AWS and navigate to the Amazon Cognito user pools console
. Choose a user pool or create a new one. -
In your user pool configuration, select the App clients menu. Choose an app client or create a new one.
-
Under App client information, select Edit.
-
Under App client flows, choose the authentication flows that you want to support.
To configure an app client for authentication flows (API/SDK)
To configure available authentication flows for an app client with the Amazon Cognito API, set the value of
ExplicitAuthFlowsin a CreateUserPoolClient or UpdateUserPoolClient request. The following is an example that provisions secure remote password (SRP) and choice-based authentication to a client."ExplicitAuthFlows": [ "ALLOW_USER_AUTH", "ALLOW_USER_SRP_AUTH" ]When you configure app client supported flows, you can specify the following options and API values.
App client flow support Authentication flow Compatibility Console API Choice-based authentication Server-side, client-side Select an authentication type at sign-in ALLOW_USER_AUTHSign-in with persistent passwords Client-side Sign in with username and password ALLOW_USER_PASSWORD_AUTHSign-in with persistent passwords and secure payload Server-side, client-side Sign in with secure remote password (SRP) ALLOW_USER_SRP_AUTHRefresh tokens Server-side, client-side Get new user tokens from existing authenticated sessions ALLOW_REFRESH_TOKEN_AUTHServer-side authentication Server-side Sign in with server-side administrative credentials ALLOW_ADMIN_USER_PASSWORD_AUTHCustom authentication Server-side and client-side custom-built applications. Not compatible with managed login. Sign in with custom authentication flows from Lambda triggers ALLOW_CUSTOM_AUTH -
- Implement flows in your application
-
Managed login automatically makes your configured authentication options available in your sign-pages. In custom-built applications, start authentication with a declaration of the initial flow.
-
To choose from a list of flow options for a user, declare choice-based authentication with the
USER_AUTHflow. This flow has available authentication methods that aren't available in client-based authentication flows, for example passkey and passwordless authentication. -
To choose your authentication flow up front, declare client-based authentication with any other flow that's available in your app client.
When you sign users in, the body of your InitiateAuth or AdminInitiateAuth request must include an
AuthFlowparameter.Choice-based authentication:
"AuthFlow": "USER_AUTH"Client-based authentication with SRP:
"AuthFlow": "USER_SRP_AUTH" -