aws.cognito_idp.create_user_pool_client ​
Call AWS Cognito IDP CreateUserPoolClient using a CloudConnection UUID.
Overview ​
| Property | Value |
|---|---|
| Workflow type | Atomic |
| Library | Base-aws |
| Version | 1.0 |
Input Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
organization_uuid | uuid | Yes | — | Authenticated organization UUID used for field resolution and connection scoping. |
connection_uuid | uuid | Yes | — | AWS CloudConnection UUID for the target Cognito IDP account, scoped to the caller organization. |
workflow_run_id | string | No | — | Engine DAG run ID stamped onto child steps. |
region | string | No | — | AWS API endpoint region override; omit to use the connection or SDK default. |
user_pool_id | string | Yes | — | The ID of the user pool where you want to create an app client. |
client_name | string | Yes | — | A friendly name for the app client that you want to create. |
generate_secret | boolean | No | — | When true, generates a client secret for the app client. Client secrets are used with server-side and machine-to-machine applications. Client secrets are automatically generated; you can't specify... |
client_secret | string | No | — | A custom client secret that you want to use for the app client. You cannot specify both GenerateSecret as true and provide a ClientSecret value. |
refresh_token_validity | integer | No | — | The refresh token time limit. After this limit expires, your user can't use their refresh token. To specify the time unit for RefreshTokenValidity as seconds, minutes, hours, or days, set a TokenVa... |
access_token_validity | integer | No | — | The access token time limit. After this limit expires, your user can't use their access token. To specify the time unit for AccessTokenValidity as seconds, minutes, hours, or days, set a TokenValid... |
id_token_validity | integer | No | — | The ID token time limit. After this limit expires, your user can't use their ID token. To specify the time unit for IdTokenValidity as seconds, minutes, hours, or days, set a TokenValidityUnits val... |
token_validity_units | json | No | — | The units that validity times are represented in. The default unit for refresh tokens is days, and the default for ID and access tokens are hours. |
read_attributes | list | No | — | The list of user attributes that you want your app client to have read access to. After your user authenticates in your app, their access token authorizes them to read their own attribute value for... |
write_attributes | list | No | — | The list of user attributes that you want your app client to have write access to. After your user authenticates in your app, their access token authorizes them to set or modify their own attribute... |
explicit_auth_flows | list | No | — | The authentication flows that you want your user pool client to support. For each app client in your user pool, you can sign in your users with any combination of one or more flows, including with... |
supported_identity_providers | list | No | — | A list of provider names for the identity providers (IdPs) that are supported on this client. The following are supported: COGNITO, Facebook, Google, SignInWithApple, and LoginWithAmazon. You can a... |
callback_urls | list | No | — | A list of allowed redirect, or callback, URLs for managed login authentication. These URLs are the paths where you want to send your users' browsers after they complete authentication with managed... |
logout_urls | list | No | — | A list of allowed logout URLs for managed login authentication. When you pass logout_uri and client_id parameters to /logout, Amazon Cognito signs out your user and redirects them to the logout URL... |
default_redirect_uri | string | No | — | The default redirect URI. In app clients with one assigned IdP, replaces redirect_uri in authentication requests. Must be in the CallbackURLs list. |
allowed_o_auth_flows | list | No | — | The OAuth grant types that you want your app client to generate for clients in managed login authentication. To create an app client that generates client credentials grants, you must add client_cr... |
allowed_o_auth_scopes | list | No | — | The OAuth, OpenID Connect (OIDC), and custom scopes that you want to permit your app client to authorize access with. Scopes govern access control to user pool self-service API operations, user dat... |
allowed_o_auth_flows_user_pool_client | boolean | No | — | Set to true to use OAuth 2.0 authorization server features in your app client. This parameter must have a value of true before you can configure the following features in your app client. CallBackU... |
analytics_configuration | json | No | — | The user pool analytics configuration for collecting metrics and sending them to your Amazon Pinpoint campaign. In Amazon Web Services Regions where Amazon Pinpoint isn't available, user pools migh... |
prevent_user_existence_errors | string | No | — | When ENABLED, suppresses messages that might indicate a valid user exists when someone attempts sign-in. This parameters sets your preference for the errors and responses that you want Amazon Cogni... |
enable_token_revocation | boolean | No | — | Activates or deactivates token revocation in the target app client. If you don't include this parameter, token revocation is automatically activated for the new user pool client. |
enable_propagate_additional_user_context_data | boolean | No | — | When true, your application can include additional UserContextData in authentication requests. This data includes the IP address, and contributes to analysis by threat protection features. For more... |
auth_session_validity | integer | No | — | Amazon Cognito creates a session token for each API request in an authentication flow. AuthSessionValidity is the duration, in minutes, of that session token. Your user pool native user must respon... |
refresh_token_rotation | json | No | — | The configuration of your app client for refresh token rotation. When enabled, your app client issues new ID, access, and refresh tokens when users renew their sessions with refresh tokens. When di... |
provider_native_request | json | No | — | Optional provider-native request overrides for AWS parameters not yet promoted to first-class fields. |
Output Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
organization_uuid | uuid | No | — | Organization UUID echoed from input. |
connection_uuid | uuid | No | — | AWS CloudConnection UUID echoed from input. |
region | string | No | — | AWS API endpoint region used. |
service | string | No | — | AWS boto3 service/client name. |
operation | string | No | — | AWS API operation invoked. |
request_id | string | No | — | AWS request ID when available. |
response | json | No | — | Sanitized provider response object. |
items | list | No | — | Primary response item list when the API returns a collection. |
result_count | integer | No | — | Count of primary response items. |
next_page_token | string | No | — | Pagination token for the next page. |
failure_reason | string | No | — | Human-readable failure reason. |
failed_step | string | No | — | Failed logical step. |
failed_layer | json | No | — | Failed DAG layer if engine supplies one. |
failed_at_state | string | No | — | State where failure occurred. |
error | string | No | — | Error message. |
error_type | string | No | — | Error class. |
failed_at | string | No | — | ISO failure timestamp. |
States ​
| State | Initial | Terminal | Success | Auto-advance | Description |
|---|---|---|---|---|---|
pending | Yes | No | — | execute | — |
completed | No | Yes | Yes | — | — |
failed | No | Yes | No | — | — |
State Diagram ​
Transitions ​
| From | Action | To | Description |
|---|---|---|---|
pending | execute | completed | — |
* (any state) | fail | failed | — |
API Usage ​
bash
POST /api/workflows/start
Content-Type: application/json
{
"workflow_type": "aws.cognito_idp.create_user_pool_client",
"initial_data": {
"organization_uuid": "value",
"connection_uuid": "value",
"user_pool_id": "value",
"client_name": "value"
}
}