Amazon Cognito
Cognito
You need to add user signup, signin, and federated identity access to your web or mobile applications.
Reach for it when
- Managing user registration, login forms, and profile database storage for a web application.
- Allowing users to sign in using social identity providers like Google, Facebook, or Apple.
- Generating temporary AWS credentials for authenticated users to access S3 or DynamoDB directly.
Do not reach for it when
- Managing machine-to-machine API credentials and internal service accounts — use IAM or Secrets Manager instead.
- Implementing complex, enterprise-level employee identity access across multiple business units — use IAM Identity Center instead.
- Building custom authorization logic that does not require user authentication — use API Gateway authorizers instead.
Alternatives, and how to choose
| Service | Pick it instead when |
|---|---|
| IAM Identity Center | Choose it when managing corporate employee access to AWS accounts and business applications. |
| IAM | Choose it when authorizing internal AWS services and application code to access cloud resources. |
How you pay
- The model
- Pay per Monthly Active User (MAU) who logs in or performs an authentication action.
- The line item that surprises people
- Enabling advanced security features like adaptive MFA or compromise credential checks dramatically increases the MAU rate.
What trips people up
- Certain user pool attributes, such as custom attributes, cannot be modified or deleted after the pool is created.
- Customizing the default hosted UI is extremely limited; branding changes often require building a custom frontend.
- Token expiration settings are restricted; check integration limits if your app requires long-lived sessions.
Verify the live service
This page is a concept reference. Cost models are qualitative; confirm the current offering, Region and pricing before deploying.