aws.cognito.sign_in ​
Authenticate a user in a Cognito User Pool (username/password)
Authenticate a user in a Cognito User Pool using the USER_PASSWORD_AUTH flow.
The app client must have "ALLOW_USER_PASSWORD_AUTH" enabled. On success returns ID, access, and refresh tokens. If Cognito returns a challenge (e.g. MFA, NEW_PASSWORD_REQUIRED), the workflow fails with WorkflowNotRetryableError and the caller must handle the challenge (e.g. via respond_to_auth_challenge) or user interaction.
Inputs:
- user_pool_id: Cognito User Pool ID (required).
- client_id: App client ID (required).
- username: User's username (or email if configured as alias) (required).
- password: User's password (required). Used in-flight only; never persisted to state_data.
Outputs (terminal state_data):
- id_token: str -- JWT ID token
- access_token: str -- JWT access token
- refresh_token: str -- refresh token for obtaining new tokens
- expires_in: int -- access token validity in seconds
- token_type: str -- "Bearer"
Plugin required: context.get_plugin("aws") must expose .cognito_idp_client().
Overview ​
| Property | Value |
|---|---|
| Workflow type | Atomic |
| Library | Base-aws |
| Version | 1.0 |
Input Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
user_pool_id | string | Yes | — | Cognito User Pool ID |
client_id | string | Yes | — | App client ID (must allow USER_PASSWORD_AUTH) |
username | string | Yes | — | User's username or sign-in alias |
password | string | Yes | — | User password (used in-flight only; not persisted to state_data) |
Output Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
id_token | string | Yes | — | JWT ID token |
access_token | string | Yes | — | JWT access token |
refresh_token | string | Yes | — | Refresh token for obtaining new tokens |
expires_in | integer | Yes | — | Access token validity in seconds |
token_type | string | Yes | — | Token type (always Bearer) |
failure_reason | string | No | — | — |
failure_type | string | No | — | — |
failed_action | string | No | — | — |
failed_at_state | string | No | — | — |
failed_step | string | No | — | — |
failed_layer | string | No | — | — |
error | string | No | — | — |
error_type | string | No | — | — |
States ​
| State | Initial | Terminal | Success | Auto-advance | Description |
|---|---|---|---|---|---|
pending | Yes | No | — | execute | — |
completed | No | Yes | Yes | — | — |
failed | No | Yes | No | — | — |
State Diagram ​
Transitions ​
| From | Action | To | Description |
|---|---|---|---|
pending | execute | completed | — |
* (any state) | fail | failed | — |
API Usage ​
bash
POST /api/workflows/start
Content-Type: application/json
{
"workflow_type": "aws.cognito.sign_in",
"initial_data": {
"user_pool_id": "value",
"client_id": "value",
"username": "value",
"password": "value"
}
}