Integrations
Connect Amazon Cognito
Connect an Amazon Cognito user pool as an Identity Provider for your API Portal. Enter a Connection Name, User Pool ID, Region, and App Client ID. Saving sends Apiable a setup request, and Apiable completes the connection.
You connect an Amazon Cognito user pool as an Identity Provider under Integrations → Identity Providers. You name the connection and enter the pool's ID, its AWS Region, and the app client's ID, then save. Saving sends Apiable a setup request, and Apiable completes the connection on its side. Once Apiable confirms, you turn the provider on and assign it to the companies whose developers should sign in through it.
Where do you connect Amazon Cognito?
Open Integrations → Identity Providers, select + Add AuthN, choose Amazon Cognito, and continue. The connection form opens on the Authorization tab.
- Open Integrations → Identity Providers.
- Select + Add AuthN. The next screen lists the provider types.
- Choose Amazon Cognito and continue to the connection form, which opens on the Authorization tab.
You can also start from Integrations → Integrations: in the Identity Providers category, choose Set up on the Amazon Cognito card.
What does each Amazon Cognito field mean?
The Authorization tab asks for a connection name and your user pool details. Required fields are marked.
| Field | What to enter |
|---|---|
| Connection Name | A name for this connection inside Apiable. Required. |
| User Pool ID | The ID of your Amazon Cognito user pool. Required. |
| Region | The AWS Region the user pool is in, for example eu-central-1. Required. |
| App Client ID | The ID of the app client in that user pool. Required. |
| Client Secret | A masked field. The value you type here is not kept with the connection. |
The Instructions panel beside the form shows the setup notes for Amazon Cognito, including the redirect address to add to your app client.
How do you save the connection and get it working?
Turn the provider off, save it, and wait for Apiable to complete the connection. Saving sends Apiable a setup request. Until Apiable completes it, an active provider's sign-in fails.
- Switch off the Active toggle above the tabs. A new provider starts active.
- Save. Apiable receives a request to connect the provider, and the Assignment tab becomes available.
- When Apiable confirms the connection, switch the Active toggle on and save.
- Test a sign-in through the provider on your API Portal. Use an email address that has no password account on the portal, because an account created with a password cannot sign in through a provider.
How do you set the display name, icon, and display mode?
Open the Details tab. Enter a Display Name, which is required, add a display icon, and choose the display mode, Standalone or Grouped. These control how the provider appears on your API Portal login page.
A Standalone provider gets its own "Continue with" button with its display name and icon, shown to every visitor. A Grouped provider sits behind the shared Sign in with SSO button and is reached only by developers whose company is assigned to it. See Identity Providers for how each mode looks.
How do you assign companies and force SSO?
Open the Assignment tab, which unlocks after the first save. Select the companies whose developers should be routed to Amazon Cognito, then save. Leave Force SSO off until sign-in works and you have checked for existing password accounts.
- On Assignment, search the Companies list and select each company, or use Select All.
- Leave Force SSO off for now.
- Save the assignment.
Assign all companies does not route developers to the provider by email domain, and saving with it on clears the companies you selected individually. See How does company assignment work?.
Troubleshooting
Match what you see to the fix. Sign-in problems show on your API Portal login page.
| What you see | What to do |
|---|---|
| The Assignment tab is greyed out | The provider has not been saved yet. Complete the Authorization tab and save, then open Assignment. |
| "This identity provider is not configured correctly. Please contact your administrator." | Apiable has not completed the connection. Turn the provider off, and turn it on when Apiable confirms. |
| Client Secret is empty when you reopen the provider | The field's value is not kept. Ask Apiable how to hand over the secret when it completes the connection. |
| The provider does not appear on the login page | Check that the Active toggle is on and the display mode is Standalone. A Grouped provider shows only through Sign in with SSO. Allow up to five minutes after a change. |
| Sign-in reaches your user pool but fails there | Recheck the User Pool ID, Region, and App Client ID, and that the app client has the redirect address from the Instructions panel. |
| "Different login method required" | The developer's account was created with a password or through another provider, and can only sign in that way. If Force SSO blocks their password, turn Force SSO off for this provider. |
| A developer still sees a password field when you expected SSO only | Force SSO is off for this provider, or the developer's company is not assigned to it. Force SSO is one switch on the Assignment tab and applies only to the companies assigned to the provider. |
Where to next
Identity Providers
How connections, assignment, and Force SSO work together.
Connect Microsoft Entra ID
Sign in developers from a Microsoft Entra ID tenant or domain.
Connect an OpenID Connect provider
Connect any standards-compliant OpenID Connect provider.
Authorization Servers
The OAuth2 side: tokens for API calls, not portal sign-in.