Skip to content
Proud to collaborate with Microsoft for Startups

aws.cognito.exchange_code_for_tokens ​

Exchange OAuth2 authorization code for tokens (callback)

Exchange an OAuth2 authorization code for ID, access, and refresh tokens.

Used after the user is redirected back from Cognito hosted UI (or an authorization endpoint) with ?code=... in the callback URL. This workflow POSTs to the Cognito token endpoint (/oauth2/token) and returns the tokens.

Supports public clients (no secret) and confidential clients (client_secret sent as Basic auth or in the body). Optional code_verifier for PKCE.

Inputs:

  • cognito_domain: Full Cognito domain host, e.g. my-app.auth.us-east-1.amazoncognito.com (required).
  • client_id: App client ID (required).
  • redirect_uri: Redirect URI used in the authorization request (required).
  • code: Authorization code from the callback query (required).
  • client_secret: App client secret; if set, used for client_secret_basic (optional).
  • code_verifier: PKCE code verifier if the authorization request used code_challenge (optional).

Outputs (terminal state_data):

  • id_token: str - JWT ID token
  • access_token: str - JWT access token
  • refresh_token: str - refresh token (only for authorization_code grant)
  • expires_in: int - access token validity in seconds
  • token_type: str - "Bearer"

Plugin required: none (uses httpx to call Cognito token endpoint over HTTPS).

Overview ​

PropertyValue
Workflow typeAtomic
LibraryBase-aws
Version1.0

Input Schema ​

FieldTypeRequiredDefaultDescription
cognito_domainstringYes—Cognito domain host, e.g. my-app.auth.us-east-1.amazoncognito.com
client_idstringYes—App client ID
redirect_uristringYes—Redirect URI used in the authorization request
codestringYes—Authorization code from the callback
client_secretstringNo—App client secret (for confidential clients)
code_verifierstringNo—PKCE code verifier if authorization used code_challenge

Output Schema ​

FieldTypeRequiredDefaultDescription
id_tokenstringYes—JWT ID token
access_tokenstringYes—JWT access token
refresh_tokenstringNo—Refresh token (authorization_code grant only)
expires_inintegerYes—Access token validity in seconds
token_typestringYes—Token type, always Bearer
failure_reasonstringNo——
failure_typestringNo——
failed_actionstringNo——
failed_at_statestringNo——
failed_stepstringNo——
failed_layerstringNo——
errorstringNo——
error_typestringNo——

States ​

StateInitialTerminalSuccessAuto-advanceDescription
pendingYesNo—execute—
completedNoYesYes——
failedNoYesNo——

State Diagram ​

Transitions ​

FromActionToDescription
pendingexecutecompleted—
* (any state)failfailed—

API Usage ​

bash
POST /api/workflows/start
Content-Type: application/json

{
  "workflow_type": "aws.cognito.exchange_code_for_tokens",
  "initial_data": {
    "cognito_domain": "value",
    "client_id": "value",
    "redirect_uri": "value",
    "code": "value"
  }
}