Agent skill

Cognito

by itsmostafa in itsmostafa/aws-agent-skills

AWS Cognito user authentication and authorization service. An agent skill from itsmostafa/aws-agent-skills.

MITAuto-check passedBackend & APIs

Install Cognito

skills CLI
$ npx skills add itsmostafa/aws-agent-skills --skill cognito -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install itsmostafa/aws-agent-skills cognito --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/itsmostafa/aws-agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cognito .claude/skills/cognito && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cognito
GitHub stars
1.2k
Used in
1 other repo
Token cost
~2.3k tokens
SKILL.md length
397 words
Files
2
Skills in repo
17
Repo updated
First seen
Licence
MIT

At a glance

AWS Cognito user authentication and authorization service. An agent skill from itsmostafa/aws-agent-skills.

  • Setting up user pools
  • SKILL.md covers Table of Contents, Core Concepts, Common Patterns and CLI Reference, plus 3 more sections
  • Calls aws; reaches cognito-idp.us-east-1.amazonaws.com; needs REFRESH_TOKEN
  • Configuring identity pools

What it does

Cognito is an agent skill from itsmostafa/aws-agent-skills. AWS Cognito user authentication and authorization service. Use when setting up user pools, configuring identity pools, implementing OAuth flows, managing user attributes, or integrating with social identity providers.

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `auth-flows.md`).

It sits in Backend & APIs, covering OAuth and OpenID Connect, Authentication and Authorization and RBAC. It works with Amazon Web Services. The repository describes itself as: AWS Skills for Agents. The licence is MIT.

When your agent uses it

  • Setting up user pools
  • Configuring identity pools
  • Implementing OAuth flows
  • Managing user attributes

Example prompts

  • “/cognito”

Requirements

  • Python 3
  • A credential in REFRESH_TOKEN

What it can do on your machine

Read from SKILL.md and the folder at commit e786d25. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • aws

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • cognito-idp.us-east-1.amazonaws.com

    Also links to:

    • docs.aws.amazon.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • REFRESH_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cognito loads about 2.3k tokens when it runs. Until then it costs about 56 tokens; SKILL.md has 397 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~56
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from itsmostafa/aws-agent-skills at commit e786d25, republished under its MIT licence (© itsmostafa). 397 words, ~2,306 tokens.

Download SKILL.mdSave it as .claude/skills/cognito/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
cognito
description
AWS Cognito user authentication and authorization service. Use when setting up user pools, configuring identity pools, implementing OAuth flows, managing user attributes, or integrating with social identity providers.
last_updated
2026-01-07
doc_source
https://docs.aws.amazon.com/cognito/latest/developerguide/

AWS Cognito

Amazon Cognito provides authentication, authorization, and user management for web and mobile applications. Users can sign in directly or through federated identity providers.

Table of Contents

Core Concepts

User Pools

User directory for sign-up and sign-in. Provides:

  • User registration and authentication
  • OAuth 2.0 / OpenID Connect tokens
  • MFA and password policies
  • Customizable UI and flows
Identity Pools (Federated Identities)

Provide temporary AWS credentials to access AWS services. Users can be:

  • Cognito User Pool users
  • Social identity (Google, Facebook, Apple)
  • SAML/OIDC enterprise identity
  • Anonymous guests
Tokens
TokenPurposeLifetime
ID TokenUser identity claims1 hour
Access TokenAPI authorization1 hour
Refresh TokenGet new ID/Access tokens30 days (configurable)

Common Patterns

Create User Pool

AWS CLI:

bash
aws cognito-idp create-user-pool \
  --pool-name my-app-users \
  --policies '{
    "PasswordPolicy": {
      "MinimumLength": 12,
      "RequireUppercase": true,
      "RequireLowercase": true,
      "RequireNumbers": true,
      "RequireSymbols": true
    }
  }' \
  --auto-verified-attributes email \
  --username-attributes email \
  --mfa-configuration OPTIONAL \
  --user-attribute-update-settings '{
    "AttributesRequireVerificationBeforeUpdate": ["email"]
  }'
Create App Client
bash
aws cognito-idp create-user-pool-client \
  --user-pool-id us-east-1_abc123 \
  --client-name my-web-app \
  --generate-secret \
  --explicit-auth-flows ALLOW_USER_SRP_AUTH ALLOW_REFRESH_TOKEN_AUTH \
  --supported-identity-providers COGNITO \
  --callback-urls https://myapp.com/callback \
  --logout-urls https://myapp.com/logout \
  --allowed-o-auth-flows code \
  --allowed-o-auth-scopes openid email profile \
  --allowed-o-auth-flows-user-pool-client \
  --access-token-validity 60 \
  --id-token-validity 60 \
  --refresh-token-validity 30 \
  --token-validity-units '{
    "AccessToken": "minutes",
    "IdToken": "minutes",
    "RefreshToken": "days"
  }'
Sign Up User
python
import boto3
import hmac
import hashlib
import base64

cognito = boto3.client('cognito-idp')

def get_secret_hash(username, client_id, client_secret):
    message = username + client_id
    dig = hmac.new(
        client_secret.encode('utf-8'),
        message.encode('utf-8'),
        digestmod=hashlib.sha256
    ).digest()
    return base64.b64encode(dig).decode()

response = cognito.sign_up(
    ClientId='client-id',
    SecretHash=get_secret_hash('user@example.com', 'client-id', 'client-secret'),
    Username='user@example.com',
    Password='SecurePassword123!',
    UserAttributes=[
        {'Name': 'email', 'Value': 'user@example.com'},
        {'Name': 'name', 'Value': 'John Doe'}
    ]
)
Confirm Sign Up
python
cognito.confirm_sign_up(
    ClientId='client-id',
    SecretHash=get_secret_hash('user@example.com', 'client-id', 'client-secret'),
    Username='user@example.com',
    ConfirmationCode='123456'
)
Authenticate User
python
response = cognito.initiate_auth(
    ClientId='client-id',
    AuthFlow='USER_SRP_AUTH',
    AuthParameters={
        'USERNAME': 'user@example.com',
        'SECRET_HASH': get_secret_hash('user@example.com', 'client-id', 'client-secret'),
        'SRP_A': srp_a  # From SRP library
    }
)

# For simple password auth (not recommended for production)
response = cognito.admin_initiate_auth(
    UserPoolId='us-east-1_abc123',
    ClientId='client-id',
    AuthFlow='ADMIN_USER_PASSWORD_AUTH',
    AuthParameters={
        'USERNAME': 'user@example.com',
        'PASSWORD': 'password',
        'SECRET_HASH': get_secret_hash('user@example.com', 'client-id', 'client-secret')
    }
)

tokens = response['AuthenticationResult']
id_token = tokens['IdToken']
access_token = tokens['AccessToken']
refresh_token = tokens['RefreshToken']
Refresh Tokens
python
response = cognito.initiate_auth(
    ClientId='client-id',
    AuthFlow='REFRESH_TOKEN_AUTH',
    AuthParameters={
        'REFRESH_TOKEN': refresh_token,
        'SECRET_HASH': get_secret_hash('user@example.com', 'client-id', 'client-secret')
    }
)
Create Identity Pool
bash
aws cognito-identity create-identity-pool \
  --identity-pool-name my-app-identities \
  --allow-unauthenticated-identities \
  --cognito-identity-providers \
    ProviderName=cognito-idp.us-east-1.amazonaws.com/us-east-1_abc123,\
ClientId=client-id,\
ServerSideTokenCheck=true
Get AWS Credentials
python
import boto3

cognito_identity = boto3.client('cognito-identity')

# Get identity ID
response = cognito_identity.get_id(
    IdentityPoolId='us-east-1:12345678-1234-1234-1234-123456789012',
    Logins={
        'cognito-idp.us-east-1.amazonaws.com/us-east-1_abc123': id_token
    }
)
identity_id = response['IdentityId']

# Get credentials
response = cognito_identity.get_credentials_for_identity(
    IdentityId=identity_id,
    Logins={
        'cognito-idp.us-east-1.amazonaws.com/us-east-1_abc123': id_token
    }
)

credentials = response['Credentials']
# Use credentials['AccessKeyId'], credentials['SecretKey'], credentials['SessionToken']

CLI Reference

User Pool
CommandDescription
aws cognito-idp create-user-poolCreate user pool
aws cognito-idp describe-user-poolGet pool details
aws cognito-idp update-user-poolUpdate pool settings
aws cognito-idp delete-user-poolDelete pool
aws cognito-idp list-user-poolsList pools
Users
CommandDescription
aws cognito-idp admin-create-userCreate user (admin)
aws cognito-idp admin-delete-userDelete user
aws cognito-idp admin-get-userGet user details
aws cognito-idp list-usersList users
aws cognito-idp admin-set-user-passwordSet password
aws cognito-idp admin-disable-userDisable user
Authentication
CommandDescription
aws cognito-idp initiate-authStart authentication
aws cognito-idp respond-to-auth-challengeRespond to MFA
aws cognito-idp admin-initiate-authAdmin authentication

Best Practices

Show full SKILL.md (160 more words)Show less
Security
  • Enable MFA for all users (at least optional)
  • Use strong password policies
  • Enable advanced security features (adaptive auth)
  • Verify email/phone before allowing sign-in
  • Use short token lifetimes for sensitive apps
  • Never expose client secrets in frontend code
User Experience
  • Use hosted UI for quick implementation
  • Customize UI with CSS
  • Implement proper error handling
  • Provide clear password requirements
Architecture
  • Use identity pools for AWS resource access
  • Use access tokens for API Gateway
  • Store refresh tokens securely
  • Implement token refresh before expiry

Troubleshooting

User Cannot Sign In

Causes:

  • User not confirmed
  • Password incorrect
  • User disabled
  • Account locked (too many attempts)

Debug:

bash
aws cognito-idp admin-get-user \
  --user-pool-id us-east-1_abc123 \
  --username user@example.com
Token Validation Failed

Causes:

  • Token expired
  • Wrong user pool/client ID
  • Token signature invalid

Validate JWT:

python
import jwt
import requests

# Get JWKS
jwks_url = f'https://cognito-idp.us-east-1.amazonaws.com/us-east-1_abc123/.well-known/jwks.json'
jwks = requests.get(jwks_url).json()

# Decode and verify (use python-jose or similar)
from jose import jwt

claims = jwt.decode(
    token,
    jwks,
    algorithms=['RS256'],
    audience='client-id',
    issuer='https://cognito-idp.us-east-1.amazonaws.com/us-east-1_abc123'
)
Hosted UI Not Working

Check:

  • Callback URLs configured correctly
  • Domain configured for user pool
  • OAuth settings enabled
bash
# Check domain
aws cognito-idp describe-user-pool \
  --user-pool-id us-east-1_abc123 \
  --query 'UserPool.Domain'
Rate Limiting

Symptom: TooManyRequestsException

Solutions:

  • Implement exponential backoff
  • Request quota increase
  • Cache tokens appropriately

References

© itsmostafa, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/cognito of itsmostafa/aws-agent-skills.

  • SKILL.md
  • auth-flows.md

Open the folder on GitHubat commit e786d25

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in itsmostafa/aws-agent-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Cognito next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cognito compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cognito this skillitsmostafa/aws-agent-skills1.2k1 repos~2.3kAutomated safety check: PassMIT
Iam Auditbriiirussell/cybersecurity-skills413—~3.1kAutomated safety check: NotesMIT
Auth Implementation Patternsynulihao/AgentSkillOS61710 repos~4.4kAutomated safety check: PassNone
Supercheck Security Authsupercheck-io/supercheck215—~1.2kAutomated safety check: PassAGPL-3.0
Authenticationcodewithmukesh/dotnet-claude-kit7551 repos~1.9kAutomated safety check: PassMIT
Spring Boot Security JWTgiuseppe-trisciuoglio/developer-kit356—~3.9kAutomated safety check: NotesMIT

Similar skills

  • Iam Audit

    briiirussell/cybersecurity-skills

    Audit, design, and migrate Identity and Access Management — cloud provider IAM (AWS, GCP, Azure), identity providers (Okta, Entra ID / Azure AD, Auth0, Google Workspace), application authorization…

    413 GitHub stars~3.1k tokensUpdated 4 mo ago
    Backend & APIsAuto-check: notes
  • Auth Implementation Patterns

    ynulihao/AgentSkillOS

    Master authentication and authorization patterns including JWT, OAuth2, session management, and RBAC to build secure, scalable access control systems.

    617 GitHub starsUsed in 10 repos~4.4k tokens
    Backend & APIsAuto-check passed
  • Supercheck Security Auth

    supercheck-io/supercheck

    Work on Supercheck authentication, RBAC, tenant isolation, sessions, API and trigger keys, invitations, project membership, project variables, OAuth, super-admin behavior, SSRF, or…

    215 GitHub stars~1.2k tokensUpdated today
    Backend & APIsAuto-check passed
  • Authentication

    codewithmukesh/dotnet-claude-kit

    Authentication and authorization for ASP.NET Core. An agent skill from codewithmukesh/dotnet-claude-kit.

    755 GitHub starsUsed in 1 repo~1.9k tokens
    Backend & APIsAuto-check passed
  • Spring Boot Security JWT

    giuseppe-trisciuoglio/developer-kit

    Provides JWT authentication and authorization patterns for Spring Boot 3.5.x covering token generation with JJWT, Bearer/cookie authentication, database/OAuth2 integration, and RBAC/permission-based…

    356 GitHub stars~3.9k tokensUpdated 28 days ago
    Backend & APIsAuto-check: notes
  • Authentication Patterns

    rohitg00/awesome-claude-code-toolkit

    Authentication and authorization patterns including OAuth2, JWT, RBAC, session management, and PKCE flows

    2.7k GitHub stars~1.4k tokensUpdated 5 mo ago
    Backend & APIsAuto-check passed

More from itsmostafa/aws-agent-skills

All 17 skills in this repo
  • API Gateway

    itsmostafa/aws-agent-skills

    AWS API Gateway for REST and HTTP API management. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub stars~2.2k tokensUpdated 3 days ago
    Auto-check passed
  • Bedrock

    itsmostafa/aws-agent-skills

    AWS Bedrock foundation models for generative AI. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub stars~4.9k tokensUpdated 3 days ago
    Auto-check passed
  • Cloudformation

    itsmostafa/aws-agent-skills

    AWS CloudFormation infrastructure as code for stack management.

    1.2k GitHub stars~2.5k tokensUpdated 3 days ago
    Auto-check passed
  • Cloudwatch

    itsmostafa/aws-agent-skills

    AWS CloudWatch monitoring for logs, metrics, alarms, and dashboards.

    1.2k GitHub stars~3.5k tokensUpdated 3 days ago
    Auto-check passed
  • Dynamodb

    itsmostafa/aws-agent-skills

    AWS DynamoDB NoSQL database for scalable data storage. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub stars~2.5k tokensUpdated 3 days ago
    Auto-check passed
  • Ecs

    itsmostafa/aws-agent-skills

    AWS ECS container orchestration for running Docker containers.

    1.2k GitHub stars~4.7k tokensUpdated 3 days ago
    Auto-check passed

Categories

Questions about Cognito

What does Cognito do?

AWS Cognito user authentication and authorization service. An agent skill from itsmostafa/aws-agent-skills. Cognito is an agent skill from itsmostafa/aws-agent-skills. AWS Cognito user authentication and authorization service.

When should I use Cognito?

Cognito fits situations like: setting up user pools; configuring identity pools; implementing OAuth flows; managing user attributes.

How do I install Cognito in Claude Code?

Run `npx skills add itsmostafa/aws-agent-skills --skill cognito -a claude-code`. Or copy the skill folder (skills/cognito in itsmostafa/aws-agent-skills) into .claude/skills/cognito in your project. Claude Code loads it when a task matches its description.

How do I install Cognito in Codex?

Run `npx skills add itsmostafa/aws-agent-skills --skill cognito -a codex`. Or copy the skill folder (skills/cognito in itsmostafa/aws-agent-skills) into .agents/skills/cognito in your project. Codex loads it when a task matches its description.

Can I use Cognito in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add itsmostafa/aws-agent-skills --skill cognito -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cognito, .gemini/skills/cognito, .github/skills/cognito and .opencode/skills/cognito in your project.

What does Cognito need to run?

Going by SKILL.md and its folder, Cognito needs the command-line tools its instructions call (aws) and credentials named REFRESH_TOKEN. Our summary lists: Python 3; A credential in REFRESH_TOKEN.

Does Cognito access the network?

SKILL.md names 2 domains. In commands or code: cognito-idp.us-east-1.amazonaws.com; the agent is likely to contact it when it follows the instructions. As links in the text: docs.aws.amazon.com. This is read from the text; nothing was executed.

Is Cognito safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cognito use?

Cognito is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cognito use?

About 2.3k tokens (SKILL.md is roughly 9.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Cognito?

Skills that share tags, products or a category with Cognito: Iam Audit (briiirussell/cybersecurity-skills, 413 stars), Auth Implementation Patterns (ynulihao/AgentSkillOS, 617 stars), Supercheck Security Auth (supercheck-io/supercheck, 215 stars) and Authentication (codewithmukesh/dotnet-claude-kit, 755 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cognito?

itsmostafa (a GitHub user) maintains it in itsmostafa/aws-agent-skills, which has 1,162 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 5, 2026.

Source: itsmostafa/aws-agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.