Apiable

Integrations

Connect Amazon Cognito

Connect an Amazon Cognito user pool as an Identity Provider for your API Portal. Enter a Connection Name, User Pool ID, Region, and App Client ID. Saving sends Apiable a setup request, and Apiable completes the connection.

You connect an Amazon Cognito user pool as an Identity Provider under Integrations → Identity Providers. You name the connection and enter the pool's ID, its AWS Region, and the app client's ID, then save. Saving sends Apiable a setup request, and Apiable completes the connection on its side. Once Apiable confirms, you turn the provider on and assign it to the companies whose developers should sign in through it.

Where do you connect Amazon Cognito?

Open Integrations → Identity Providers, select + Add AuthN, choose Amazon Cognito, and continue. The connection form opens on the Authorization tab.

  1. Open Integrations → Identity Providers.
  2. Select + Add AuthN. The next screen lists the provider types.
  3. Choose Amazon Cognito and continue to the connection form, which opens on the Authorization tab.

You can also start from Integrations → Integrations: in the Identity Providers category, choose Set up on the Amazon Cognito card.

What does each Amazon Cognito field mean?

The Authorization tab asks for a connection name and your user pool details. Required fields are marked.

FieldWhat to enter
Connection NameA name for this connection inside Apiable. Required.
User Pool IDThe ID of your Amazon Cognito user pool. Required.
RegionThe AWS Region the user pool is in, for example eu-central-1. Required.
App Client IDThe ID of the app client in that user pool. Required.
Client SecretA masked field. The value you type here is not kept with the connection.

The Instructions panel beside the form shows the setup notes for Amazon Cognito, including the redirect address to add to your app client.

How do you save the connection and get it working?

Turn the provider off, save it, and wait for Apiable to complete the connection. Saving sends Apiable a setup request. Until Apiable completes it, an active provider's sign-in fails.

  1. Switch off the Active toggle above the tabs. A new provider starts active.
  2. Save. Apiable receives a request to connect the provider, and the Assignment tab becomes available.
  3. When Apiable confirms the connection, switch the Active toggle on and save.
  4. Test a sign-in through the provider on your API Portal. Use an email address that has no password account on the portal, because an account created with a password cannot sign in through a provider.

How do you set the display name, icon, and display mode?

Open the Details tab. Enter a Display Name, which is required, add a display icon, and choose the display mode, Standalone or Grouped. These control how the provider appears on your API Portal login page.

A Standalone provider gets its own "Continue with" button with its display name and icon, shown to every visitor. A Grouped provider sits behind the shared Sign in with SSO button and is reached only by developers whose company is assigned to it. See Identity Providers for how each mode looks.

How do you assign companies and force SSO?

Open the Assignment tab, which unlocks after the first save. Select the companies whose developers should be routed to Amazon Cognito, then save. Leave Force SSO off until sign-in works and you have checked for existing password accounts.

  1. On Assignment, search the Companies list and select each company, or use Select All.
  2. Leave Force SSO off for now.
  3. Save the assignment.

Assign all companies does not route developers to the provider by email domain, and saving with it on clears the companies you selected individually. See How does company assignment work?.

Troubleshooting

Match what you see to the fix. Sign-in problems show on your API Portal login page.

What you seeWhat to do
The Assignment tab is greyed outThe provider has not been saved yet. Complete the Authorization tab and save, then open Assignment.
"This identity provider is not configured correctly. Please contact your administrator."Apiable has not completed the connection. Turn the provider off, and turn it on when Apiable confirms.
Client Secret is empty when you reopen the providerThe field's value is not kept. Ask Apiable how to hand over the secret when it completes the connection.
The provider does not appear on the login pageCheck that the Active toggle is on and the display mode is Standalone. A Grouped provider shows only through Sign in with SSO. Allow up to five minutes after a change.
Sign-in reaches your user pool but fails thereRecheck the User Pool ID, Region, and App Client ID, and that the app client has the redirect address from the Instructions panel.
"Different login method required"The developer's account was created with a password or through another provider, and can only sign in that way. If Force SSO blocks their password, turn Force SSO off for this provider.
A developer still sees a password field when you expected SSO onlyForce SSO is off for this provider, or the developer's company is not assigned to it. Force SSO is one switch on the Assignment tab and applies only to the companies assigned to the provider.

Where to next