AWS CloudFormation
User Guide (Version )

The AWS Documentation website is getting a new look!
Try it now and let us know what you think. Switch to the new look >>

You can return to the original look by selecting English in the language selector above.

AWS::Cognito::IdentityPool CognitoIdentityProvider

CognitoIdentityProvider is a property of the AWS::Cognito::IdentityPool resource that represents an Amazon Cognito user pool and its client ID.


To declare this entity in your AWS CloudFormation template, use the following syntax:


{ "ClientId" : String, "ProviderName" : String, "ServerSideTokenCheck" : Boolean }


ClientId: String ProviderName: String ServerSideTokenCheck: Boolean



The client ID for the Amazon Cognito user pool.

Required: No

Type: String

Update requires: No interruption


The provider name for an Amazon Cognito user pool. For example,

Required: No

Type: String

Update requires: No interruption


TRUE if server-side token validation is enabled for the identity provider’s token.

Once you set ServerSideTokenCheck to TRUE for an identity pool, that identity pool will check with the integrated user pools to make sure that the user has not been globally signed out or deleted before the identity pool provides an OIDC token or AWS credentials for the user.

If the user is signed out or deleted, the identity pool will return a 400 Not Authorized error.

Required: No

Type: Boolean

Update requires: No interruption

On this page: