Package-level declarations

Types

Link copied to clipboard

The settings for user message delivery in forgot-password operations. Contains preference for email or SMS message delivery of password reset codes, or for admin-only password reset.

Link copied to clipboard

A list of account-takeover actions for each level of risk that Amazon Cognito might assess with threat protection features.

Link copied to clipboard

The automated response to a risk level for adaptive authentication in full-function, or ENFORCED, mode. You can assign an action to each risk level that threat protection evaluates.

Link copied to clipboard
Link copied to clipboard

The settings for automated responses and notification templates for adaptive authentication with threat protection features.

Link copied to clipboard

Represents the request to add custom attributes.

Link copied to clipboard

Represents the response from the server for the request to add custom attributes.

Link copied to clipboard

Confirm a user's registration as a user pool administrator.

Link copied to clipboard

Represents the response from the server for the request to confirm registration.

Link copied to clipboard

The settings for administrator creation of users in a user pool. Contains settings for allowing user sign-up, customizing invitation messages to new users, and the amount of time before temporary passwords expire.

Link copied to clipboard

Creates a new user in the specified user pool.

Link copied to clipboard

Represents the response from the server to the request to create the user.

Link copied to clipboard

Represents the request to delete user attributes as an administrator.

Link copied to clipboard

Represents the response received from the server for a request to delete user attributes.

Link copied to clipboard

Represents the request to delete a user as an administrator.

Link copied to clipboard
Link copied to clipboard

Represents the request to disable the user as an administrator.

Link copied to clipboard

Represents the response received from the server to disable the user as an administrator.

Link copied to clipboard

Represents the request that enables the user as an administrator.

Link copied to clipboard

Represents the response from the server for the request to enable a user as an administrator.

Link copied to clipboard

Sends the forgot device request, as an administrator.

Link copied to clipboard
Link copied to clipboard

Represents the request to get the device, as an administrator.

Link copied to clipboard

Gets the device response, as an administrator.

Link copied to clipboard

Represents the request to get the specified user as an administrator.

Link copied to clipboard

Represents the response from the server from the request to get the specified user as an administrator.

Link copied to clipboard

Initiates the authorization request, as an administrator.

Link copied to clipboard

Initiates the authentication response, as an administrator.

Link copied to clipboard

Represents the request to list devices, as an administrator.

Link copied to clipboard

Lists the device's response, as an administrator.

Link copied to clipboard

Represents the request to reset a user's password as an administrator.

Link copied to clipboard

Represents the response from the server to reset a user password as an administrator.

Link copied to clipboard

The request to respond to the authentication challenge, as an administrator.

Link copied to clipboard

Responds to the authentication challenge, as an administrator.

Link copied to clipboard

You can use this parameter to set an MFA configuration that uses the SMS delivery medium.

Link copied to clipboard

Represents the response from the server to set user settings as an administrator.

Link copied to clipboard

The request to update the device status, as an administrator.

Link copied to clipboard

The status response to the request to update the device, as an administrator.

Link copied to clipboard

Represents the request to update the user's attributes as an administrator.

Link copied to clipboard

Represents the response from the server for the request to update user attributes as an administrator.

Link copied to clipboard

The request to sign out of all devices, as an administrator.

Link copied to clipboard

The global sign-out response, as an administrator.

Link copied to clipboard

Threat protection configuration options for additional authentication types in your user pool, including custom authentication.

Link copied to clipboard
Link copied to clipboard
sealed class AliasAttributeType
Link copied to clipboard

This exception is thrown when a user tries to confirm the account with an email address or phone number that has already been supplied as an alias for a different user profile. This exception indicates that an account with this email address or phone already exists in a user pool that you've configured to use email address or phone number as a sign-in alias.

Link copied to clipboard

The settings for Amazon Pinpoint analytics configuration. With an analytics configuration, your application can collect user-activity metrics for user notifications with a Amazon Pinpoint campaign.

Link copied to clipboard

Information that your application adds to authentication requests. Applies an endpoint ID to the analytics data that your user pool sends to Amazon Pinpoint.

Link copied to clipboard
sealed class AssetCategoryType
Link copied to clipboard
sealed class AssetExtensionType
Link copied to clipboard
class AssetType

An image file from a managed login branding style in a user pool.

Link copied to clipboard
sealed class AttributeDataType
Link copied to clipboard

The name and value of a user attribute.

Link copied to clipboard

The object that your application receives after authentication. Contains tokens and information for device authentication.

Link copied to clipboard

One authentication event that Amazon Cognito logged in a user pool with threat protection active. Contains user and device metadata and a risk assessment from your user pool.

Link copied to clipboard
sealed class AuthFactorType
Link copied to clipboard
sealed class AuthFlowType
Link copied to clipboard
sealed class ChallengeName
Link copied to clipboard
sealed class ChallengeNameType
Link copied to clipboard
sealed class ChallengeResponse
Link copied to clipboard

The responses to the challenge that you received in the previous request. Each challenge has its own required response parameters. The following examples are partial JSON request bodies that highlight challenge-response parameters.

Link copied to clipboard

Represents the request to change a user password.

Link copied to clipboard

The response from the server to the change password request.

Link copied to clipboard

Configuration for the CloudWatch log group destination of user pool detailed activity logging, or of user activity log export with threat protection.

Link copied to clipboard

The delivery details for an email or SMS message that Amazon Cognito sent for authentication or verification.

Link copied to clipboard

This exception is thrown when a verification code fails to deliver successfully.

Link copied to clipboard

This exception is thrown if the provided code doesn't match what the server was expecting.

Link copied to clipboard

Base class for all service related exceptions thrown by the CognitoIdentityProvider client

Link copied to clipboard
sealed class ColorSchemeModeType
Link copied to clipboard

Settings for user pool actions when Amazon Cognito detects compromised credentials with threat protection in full-function ENFORCED mode.

Settings for compromised-credentials actions and authentication-event sources with threat protection in full-function ENFORCED mode.

Link copied to clipboard

This exception is thrown if two or more modifications are happening concurrently.

Link copied to clipboard

The confirm-device request.

Link copied to clipboard

The confirm-device response.

Link copied to clipboard

The request representing the confirmation for a password reset.

Link copied to clipboard

The response from the server that results from a user's request to retrieve a forgotten password.

Link copied to clipboard

Represents the request to confirm registration of a user.

Link copied to clipboard

Represents the response from the server for the registration confirmation.

Link copied to clipboard

Contextual user data used for evaluating the risk of an authentication event by user pool threat protection.

Link copied to clipboard
Link copied to clipboard
Link copied to clipboard

Represents the request to create the user import job.

Link copied to clipboard

Represents the response from the server to the request to create the user import job.

Link copied to clipboard

Represents the request to create a user pool client.

Link copied to clipboard

Represents the response from the server to create a user pool client.

Link copied to clipboard

Represents the request to create a user pool.

Link copied to clipboard

Represents the response from the server for the request to create a user pool.

Link copied to clipboard

The configuration for a hosted UI custom domain.

Link copied to clipboard

The properties of a custom email sender Lambda trigger.

Link copied to clipboard

The properties of a custom SMS sender Lambda trigger.

Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard

Represents the request to delete user attributes.

Link copied to clipboard

Represents the response from the server to delete user attributes.

Link copied to clipboard

Represents the request to delete a user pool client.

Link copied to clipboard

Represents the request to delete a user pool.

Link copied to clipboard
Link copied to clipboard

Represents the request to delete a user.

Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
sealed class DeliveryMediumType
Link copied to clipboard

Represents the request to describe the user import job.

Link copied to clipboard

Represents the response from the server to the request to describe the user import job.

Link copied to clipboard

Represents the request to describe a user pool client.

Link copied to clipboard

Represents the response from the server from a request to describe the user pool client.

Link copied to clipboard

Represents the request to describe the user pool.

Link copied to clipboard

Represents the response to describe the user pool.

Link copied to clipboard

The device-remembering configuration for a user pool.

Link copied to clipboard

This exception is thrown when a user attempts to confirm a device with a device key that already exists.

Link copied to clipboard
Link copied to clipboard

A Secure Remote Password (SRP) value that your application generates when you register a user's device. For more information, see Getting a device key.

Link copied to clipboard

Information about a user's device that they've registered for device SRP authentication in your application. For more information, see Working with user devices in your user pool.

Link copied to clipboard

A container for information about the user pool domain associated with the hosted UI and OAuth endpoints.

Link copied to clipboard
sealed class DomainStatusType
Link copied to clipboard

This exception is thrown when the provider is already supported by the user pool.

Link copied to clipboard

The email configuration of your user pool. The email configuration type sets your preferred sending method, Amazon Web Services Region, and sender for messages from your user pool.

Link copied to clipboard

Sets or shows configuration for user pool email message MFA and sign-in with one-time passwords (OTPs). Includes the subject and body of the email message template for sign-in and MFA messages. To activate this setting, your user pool must be in the Essentials tier or higher.

Link copied to clipboard

User preferences for multi-factor authentication with email messages. Activates or deactivates email MFA and sets it as the preferred MFA method when multiple methods are available. To activate this setting, your user pool must be in the Essentials tier or higher.

Link copied to clipboard
Link copied to clipboard

This exception is thrown when there is a code mismatch and the service fails to configure the software token TOTP multi-factor authentication (MFA).

Link copied to clipboard

The context data that your application submitted in an authentication request with threat protection, as displayed in an AdminListUserAuthEvents response.

Link copied to clipboard

The feedback that your application submitted to a threat protection event log, as displayed in an AdminListUserAuthEvents response.

Link copied to clipboard
sealed class EventFilterType
Link copied to clipboard
sealed class EventResponseType
Link copied to clipboard

The risk evaluation by adaptive authentication, as displayed in an AdminListUserAuthEvents response. Contains evaluations of compromised-credentials detection and assessed risk level and action taken by adaptive authentication.

Link copied to clipboard
sealed class EventSourceName
Link copied to clipboard
sealed class EventType
Link copied to clipboard

This exception is thrown if a code has expired.

Link copied to clipboard
Link copied to clipboard
sealed class FeatureType
Link copied to clipboard

This exception is thrown when a feature you attempted to configure isn't available in your current feature plan.

Link copied to clipboard
sealed class FeedbackValueType
Link copied to clipboard

Configuration for the Amazon Data Firehose stream destination of user activity log export with threat protection.

Link copied to clipboard

This exception is thrown when WAF doesn't allow your request based on a web ACL that's associated with your user pool.

Link copied to clipboard

Represents the request to forget the device.

Link copied to clipboard
Link copied to clipboard

Represents the request to reset a user's password.

Link copied to clipboard

The response from Amazon Cognito to a request to reset a password.

Link copied to clipboard

Represents the request to get the header information of the CSV file for the user import job.

Link copied to clipboard

Represents the response from the server to the request to get the header information of the CSV file for the user import job.

Link copied to clipboard

Represents the request to get the device.

Link copied to clipboard

Gets the device response.

Link copied to clipboard
Link copied to clipboard
Link copied to clipboard

Request to get a signing certificate from Amazon Cognito.

Link copied to clipboard

Response from Amazon Cognito for a signing certificate request.

Link copied to clipboard
Link copied to clipboard

Represents the request to get user attribute verification.

Link copied to clipboard

The verification code response returned by the server response to get the user attribute verification code.

Link copied to clipboard
Link copied to clipboard

Represents the request to get information about the user.

Link copied to clipboard

Represents the response from the server from the request to get information about the user.

Link copied to clipboard

Represents the request to sign out all devices.

Link copied to clipboard

The response to the request to sign out all devices.

Link copied to clipboard

This exception is thrown when Amazon Cognito encounters a group that already exists in the user pool.

Link copied to clipboard
class GroupType

A user pool group. Contains details about the group and the way that it contributes to IAM role decisions with identity pools. Identity pools can make decisions about the IAM role to assign based on groups: users get credentials for the role associated with their highest-priority group.

Link copied to clipboard

The HTTP header in the ContextData parameter.

Link copied to clipboard

A user pool identity provider (IdP). Contains information about a third-party IdP to a user pool, the attributes that it populates to user profiles, and the trust relationship between the IdP and your user pool.

Link copied to clipboard
Link copied to clipboard

Initiates the authentication request.

Link copied to clipboard

Initiates the authentication response.

Link copied to clipboard

This exception is thrown when Amazon Cognito encounters an internal error.

Link copied to clipboard

This exception is thrown when Amazon Cognito isn't allowed to use your email identity. HTTP status code: 400.

Link copied to clipboard

This exception is thrown when Amazon Cognito encounters an invalid Lambda response.

Link copied to clipboard

This exception is thrown when the specified OAuth flow is not valid.

Link copied to clipboard

This exception is thrown when the Amazon Cognito service encounters an invalid parameter.

Link copied to clipboard

This exception is thrown when Amazon Cognito encounters an invalid password.

Link copied to clipboard

This exception is returned when the role provided for SMS configuration doesn't have permission to publish using Amazon SNS.

Link copied to clipboard

This exception is thrown when the trust relationship is not valid for the role provided for SMS configuration. This can happen if you don't trust cognito-idp.amazonaws.com or the external ID provided in the role does not match what is provided in the SMS configuration for the user pool.

Link copied to clipboard

This exception is thrown when the user pool configuration is not valid.

Link copied to clipboard

A collection of user pool Lambda triggers. Amazon Cognito invokes triggers at several possible stages of user pool operations. Triggers can modify the outcome of the operations that invoked them.

Link copied to clipboard

This exception is thrown when a user exceeds the limit for a requested Amazon Web Services resource.

Link copied to clipboard

Represents the request to list the devices.

Link copied to clipboard

Represents the response to list devices.

Link copied to clipboard
Link copied to clipboard
Link copied to clipboard

Represents the request to list the user import jobs.

Link copied to clipboard

Represents the response from the server to the request to list the user import jobs.

Link copied to clipboard

Represents the request to list the user pool clients.

Link copied to clipboard

Represents the response from the server that lists user pool clients.

Link copied to clipboard

Represents the request to list user pools.

Link copied to clipboard

Represents the response to list user pools.

Link copied to clipboard
Link copied to clipboard
Link copied to clipboard

Represents the request to list users.

Link copied to clipboard

The response from the request to list users.

Link copied to clipboard

The configuration of user event logs to an external Amazon Web Services service like Amazon Data Firehose, Amazon S3, or Amazon CloudWatch Logs.

Link copied to clipboard

The logging parameters of a user pool, as returned in the response to a GetLogDeliveryConfiguration request.

Link copied to clipboard
sealed class LogLevel
Link copied to clipboard

This exception is thrown when you attempt to apply a managed login branding style to an app client that already has an assigned style.

Link copied to clipboard

A managed login branding style that's assigned to a user pool app client.

Link copied to clipboard
sealed class MessageActionType
Link copied to clipboard

The message template structure.

Link copied to clipboard

This exception is thrown when Amazon Cognito can't find a multi-factor authentication (MFA) method.

Link copied to clipboard

This data type is no longer supported. Applies only to SMS multi-factor authentication (MFA) configurations. Does not apply to time-based one-time password (TOTP) software token MFA configurations.

Link copied to clipboard

Information that your user pool responds with in AuthenticationResultwhen you configure it to remember devices and a user signs in with an unrecognized device. Amazon Cognito presents a new device key that you can use to set up device authentication in a "Remember me on this device" authentication model.

Link copied to clipboard

This exception is thrown when a user isn't authorized.

Link copied to clipboard

The configuration for Amazon SES email messages that threat protection sends to a user when your adaptive authentication automated response has a Notify action.

Link copied to clipboard

The template for email messages that threat protection sends to a user when your threat protection automated response has a Notify action.

Link copied to clipboard

The minimum and maximum values of an attribute that is of the number type, for example custom:age.

Link copied to clipboard
sealed class OAuthFlowType
Link copied to clipboard

The message returned when a user's new password matches a previous password and doesn't comply with the password-history policy.

Link copied to clipboard

The password policy settings for a user pool, including complexity, history, and length requirements.

Link copied to clipboard

This exception is thrown when a password reset is required.

Link copied to clipboard

This exception is thrown when a precondition is not met.

Link copied to clipboard

The properties of a pre token generation Lambda trigger.

Link copied to clipboard
Link copied to clipboard

The details of a user pool identity provider (IdP), including name and type.

Link copied to clipboard

The characteristics of a source or destination user for linking a federated user profile to a local user profile.

Link copied to clipboard
Link copied to clipboard

A recovery option for a user. The AccountRecoverySettingType data type is an array of this object. Each RecoveryOptionType has a priority property that determines whether it is a primary or secondary option.

Link copied to clipboard

This exception is throw when your application requests token refresh with a refresh token that has been invalidated by refresh-token rotation.

Link copied to clipboard

The configuration of your app client for refresh token rotation. When enabled, your app client issues new ID, access, and refresh tokens when users renew their sessions with refresh tokens. When disabled, token refresh issues only ID and access tokens.

Link copied to clipboard

Represents the request to resend the confirmation code.

Link copied to clipboard

The response from the server when Amazon Cognito makes the request to resend a confirmation code.

Link copied to clipboard

This exception is thrown when the Amazon Cognito service can't find the requested resource.

Link copied to clipboard

One custom scope associated with a user pool resource server. This data type is a member of ResourceServerScopeType. For more information, see Scopes, M2M, and API authorization with resource servers.

Link copied to clipboard

The details of a resource server configuration and associated custom scopes in a user pool.

Link copied to clipboard

The request to respond to an authentication challenge.

Link copied to clipboard

The response to respond to the authentication challenge.

Link copied to clipboard
Link copied to clipboard
Link copied to clipboard

The settings of risk configuration for threat protection with threat protection in a user pool.

Link copied to clipboard
sealed class RiskDecisionType
Link copied to clipboard

Exceptions to the risk evaluation configuration, including always-allow and always-block IP address ranges.

Link copied to clipboard
sealed class RiskLevelType
Link copied to clipboard

Configuration for the Amazon S3 bucket destination of user activity log export with threat protection.

Link copied to clipboard

A list of the user attributes and their properties in your user pool. The attribute schema contains standard attributes, custom attributes with a custom: prefix, and developer attributes with a dev: prefix. For more information, see User pool attributes.

Link copied to clipboard

This exception is thrown when the specified scope doesn't exist.

Link copied to clipboard
Link copied to clipboard

Represents the request to set user settings.

Link copied to clipboard

The response from the server for a set user settings request.

Link copied to clipboard

The policy for allowed types of authentication in a user pool. To activate this setting, your user pool must be in the Essentials tier or higher.

Link copied to clipboard

Represents the request to register a user.

Link copied to clipboard

The response from the server for a registration request.

Link copied to clipboard

User pool configuration for delivery of SMS messages with Amazon Simple Notification Service. To send SMS messages with Amazon SNS in the Amazon Web Services Region that you want, the Amazon Cognito user pool uses an Identity and Access Management (IAM) role in your Amazon Web Services account.

Link copied to clipboard

The configuration of multi-factor authentication (MFA) with SMS messages in a user pool.

Link copied to clipboard

A user's preference for using SMS message multi-factor authentication (MFA). Turns SMS MFA on and off, and can set SMS as preferred when other MFA options are available. You can't turn off SMS MFA for any of your users when MFA is required in your user pool; you can only set the type that your user prefers.

Link copied to clipboard

Settings for time-based one-time password (TOTP) multi-factor authentication (MFA) in a user pool. Enables and disables availability of this feature.

Link copied to clipboard

This exception is thrown when the software token time-based one-time password (TOTP) multi-factor authentication (MFA) isn't activated for the user pool.

Link copied to clipboard

A user's preference for using time-based one-time password (TOTP) multi-factor authentication (MFA). Turns TOTP MFA on and off, and can set TOTP as preferred when other MFA options are available. You can't turn off TOTP MFA for any of your users when MFA is required in your user pool; you can only set the type that your user prefers.

Link copied to clipboard

Represents the request to start the user import job.

Link copied to clipboard

Represents the response from the server to the request to start the user import job.

Link copied to clipboard
sealed class StatusType
Link copied to clipboard

Represents the request to stop the user import job.

Link copied to clipboard

Represents the response from the server to the request to stop the user import job.

Link copied to clipboard

The minimum and maximum length values of an attribute that is of the string type, for example custom:department.

Link copied to clipboard
Link copied to clipboard
Link copied to clipboard

This exception is thrown when you've attempted to change your feature plan but the operation isn't permitted.

Link copied to clipboard
sealed class TimeUnitsType
Link copied to clipboard

The time units that, with IdTokenValidity, AccessTokenValidity, and RefreshTokenValidity, set and display the duration of ID, access, and refresh tokens for an app client. You can assign a separate token validity unit to each type of token.

Link copied to clipboard

This exception is thrown when the user has made too many failed attempts for a given action, such as sign-in.

Link copied to clipboard

This exception is thrown when the user has made too many requests for a given operation.

Link copied to clipboard

A container for the UI customization information for the hosted UI in a user pool.

Link copied to clipboard

Exception that is thrown when the request isn't authorized. This can happen due to an invalid access token in the request.

Link copied to clipboard

This exception is thrown when Amazon Cognito encounters an unexpected exception with Lambda.

Link copied to clipboard

This exception is thrown when the specified identifier isn't supported.

Link copied to clipboard

Exception that is thrown when you attempt to perform an operation that isn't enabled for the user pool client.

Link copied to clipboard

Exception that is thrown when an unsupported token is passed to an operation.

Link copied to clipboard

The request failed because the user is in an unsupported state.

Link copied to clipboard
Link copied to clipboard
Link copied to clipboard

Represents the request to update the device status.

Link copied to clipboard

The response to the request to update the device status.

Link copied to clipboard
Link copied to clipboard
Link copied to clipboard

Represents the request to update user attributes.

Link copied to clipboard

Represents the response from the server for the request to update user attributes.

Link copied to clipboard

Represents the request to update the user pool client.

Link copied to clipboard

Represents the response from the server to the request to update the user pool client.

Link copied to clipboard

The UpdateUserPoolDomain request input.

Link copied to clipboard

The UpdateUserPoolDomain response output.

Link copied to clipboard

Represents the request to update the user pool.

Link copied to clipboard

Represents the response from the server when you make a request to update the user pool.

Link copied to clipboard

The settings for updates to user attributes. These settings include the property AttributesRequireVerificationBeforeUpdate, a user-pool setting that tells Amazon Cognito how to handle changes to the value of your users' email address and phone number attributes. For more information, see Verifying updates to email addresses and phone numbers.

Link copied to clipboard

Contextual data, such as the user's device fingerprint, IP address, or location, used for evaluating the risk of an unexpected event by Amazon Cognito threat protection.

Link copied to clipboard

This exception is thrown when you're trying to modify a user pool while a user import job is in progress for that pool.

Link copied to clipboard
Link copied to clipboard

A user import job in a user pool. Describes the status of user import with a CSV file. For more information, see Importing users into user pools from a CSV file.

Link copied to clipboard

This exception is thrown when the Amazon Cognito service encounters a user validation exception with the Lambda service.

Link copied to clipboard
Link copied to clipboard

The configuration of a user pool for username case sensitivity.

Link copied to clipboard

This exception is thrown when Amazon Cognito encounters a user name that already exists in the user pool.

Link copied to clipboard

This exception is thrown when a user isn't confirmed successfully.

Link copied to clipboard

This exception is thrown when a user isn't found.

Link copied to clipboard

This exception is thrown when user pool add-ons aren't enabled.

Link copied to clipboard

Contains settings for activation of threat protection, including the operating mode and additional authentication types. To log user security information but take no action, set to AUDIT. To configure automatic security responses to potentially unwanted traffic to your user pool, set to ENFORCED.

Link copied to clipboard

A short description of a user pool app client.

Link copied to clipboard

The configuration of a user pool client.

Link copied to clipboard

A short description of a user pool.

Link copied to clipboard
sealed class UserPoolMfaType
Link copied to clipboard

A list of user pool policies. Contains the policy that sets password-complexity requirements.

Link copied to clipboard

This exception is thrown when a user pool tag can't be set or updated.

Link copied to clipboard
sealed class UserPoolTierType
Link copied to clipboard

The configuration of a user pool.

Link copied to clipboard
sealed class UserStatusType
Link copied to clipboard
class UserType

A user profile in a Amazon Cognito user pool.

Link copied to clipboard
Link copied to clipboard

The template for the verification message that your user pool delivers to users who set an email address or phone number attribute.

Link copied to clipboard
Link copied to clipboard

Represents the request to verify user attributes.

Link copied to clipboard

A container representing the response from the server from the request to verify user attributes.

Link copied to clipboard

This exception is thrown when the challenge from StartWebAuthn registration has expired.

Link copied to clipboard

This exception is thrown when the access token is for a different client than the one in the original StartWebAuthnRegistration request.

Link copied to clipboard

This exception is thrown when a user pool doesn't have a configured relying party id or a user pool domain.

Link copied to clipboard

Settings for authentication (MFA) with passkey, or webauthN, biometric and security-key devices in a user pool. Configures the following:

Link copied to clipboard

The details of a passkey, or webauthN, biometric or security-key authentication factor for a user.

Link copied to clipboard

This exception is thrown when a user presents passkey credentials from an unsupported device or provider.

Link copied to clipboard

This exception is thrown when the passkey feature isn't enabled for the user pool.

Link copied to clipboard

This exception is thrown when the passkey credential's registration origin does not align with the user pool relying party id.

Link copied to clipboard

This exception is thrown when the given passkey credential is associated with a different relying party ID than the user pool relying party ID.