aws.cognito_idp.create_identity_provider ​
Call AWS Cognito IDP CreateIdentityProvider using a CloudConnection UUID.
Overview ​
| Property | Value |
|---|---|
| Workflow type | Atomic |
| Library | Base-aws |
| Version | 1.0 |
Input Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
organization_uuid | uuid | Yes | — | Authenticated organization UUID used for field resolution and connection scoping. |
connection_uuid | uuid | Yes | — | AWS CloudConnection UUID for the target Cognito IDP account, scoped to the caller organization. |
workflow_run_id | string | No | — | Engine DAG run ID stamped onto child steps. |
region | string | No | — | AWS API endpoint region override; omit to use the connection or SDK default. |
user_pool_id | string | Yes | — | The Id of the user pool where you want to create an IdP. |
provider_name | string | Yes | — | The name that you want to assign to the IdP. You can pass the identity provider name in the identity_provider query parameter of requests to the Authorize endpoint to silently redirect to sign-in w... |
provider_type | string | Yes | — | The type of IdP that you want to add. Amazon Cognito supports OIDC, SAML 2.0, Login With Amazon, Sign In With Apple, Google, and Facebook IdPs. |
provider_details | json | Yes | — | The scopes, URLs, and identifiers for your external identity provider. The following examples describe the provider detail keys for each IdP type. These values and their schema are subject to chang... |
attribute_mapping | json | No | — | A mapping of IdP attributes to standard and custom user pool attributes. Specify a user pool attribute as the key of the key-value pair, and the IdP attribute claim name as the value. |
idp_identifiers | list | No | — | An array of IdP identifiers, for example "IdPIdentifiers": [ "MyIdP", "MyIdP2" ]. Identifiers are friendly names that you can pass in the idp_identifier query parameter of requests to the Authorize... |
provider_native_request | json | No | — | Optional provider-native request overrides for AWS parameters not yet promoted to first-class fields. |
Output Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
organization_uuid | uuid | No | — | Organization UUID echoed from input. |
connection_uuid | uuid | No | — | AWS CloudConnection UUID echoed from input. |
region | string | No | — | AWS API endpoint region used. |
service | string | No | — | AWS boto3 service/client name. |
operation | string | No | — | AWS API operation invoked. |
request_id | string | No | — | AWS request ID when available. |
response | json | No | — | Sanitized provider response object. |
items | list | No | — | Primary response item list when the API returns a collection. |
result_count | integer | No | — | Count of primary response items. |
next_page_token | string | No | — | Pagination token for the next page. |
failure_reason | string | No | — | Human-readable failure reason. |
failed_step | string | No | — | Failed logical step. |
failed_layer | json | No | — | Failed DAG layer if engine supplies one. |
failed_at_state | string | No | — | State where failure occurred. |
error | string | No | — | Error message. |
error_type | string | No | — | Error class. |
failed_at | string | No | — | ISO failure timestamp. |
States ​
| State | Initial | Terminal | Success | Auto-advance | Description |
|---|---|---|---|---|---|
pending | Yes | No | — | execute | — |
completed | No | Yes | Yes | — | — |
failed | No | Yes | No | — | — |
State Diagram ​
Transitions ​
| From | Action | To | Description |
|---|---|---|---|
pending | execute | completed | — |
* (any state) | fail | failed | — |
API Usage ​
bash
POST /api/workflows/start
Content-Type: application/json
{
"workflow_type": "aws.cognito_idp.create_identity_provider",
"initial_data": {
"organization_uuid": "value",
"connection_uuid": "value",
"user_pool_id": "value",
"provider_name": "value"
}
}