Amazon Cognito now supports machine-to-machine authorization without a user pool domain
Share
Services
Amazon Cognito now supports the GetClientToken API operation, enabling app clients to obtain access tokens for machine-to-machine (M2M) authorization directly through the AWS SDK, CLI, or API — without configuring a user pool domain. This gives you an additional path to authorize service-to-service communication for applications, microservices, and automated workloads. The new GetClientToken API operation lets your app client authenticate with its client ID and secret to receive an access token authorized for custom scopes on your resource servers. As a native AWS API operation, GetClientToken integrates seamlessly with AWS SDKs and supports AWS WAF and VPC interface endpoints (AWS PrivateLink). The existing domain-based OAuth 2.0 client-credentials flow remains available. This feature is available in all AWS Regions where Amazon Cognito user pools are available. To get started, configure an app client and call GetClientToken using the AWS Management Console, CLI, or SDKs. Standard Amazon [Cognito M2M pricing](https://aws.amazon.com/cognito/pricing/) applies. See [Amazon Cognito Developer Guide](https://docs.aws.amazon.com/cognito/latest/developerguide/cognito-user-pools-define-resource-servers.html#get-client-token) and [GetClientToken API Reference](https://docs.aws.amazon.com/cognito-user-identity-pools/latest/APIReference/API%5FGetClientToken.html) for details.
What else is happening at Amazon Web Services?
Read update
Services
Share
Amazon Redshift now supports AWS IAM Identity Center authentication with enhanced VPC routing
about 9 hours ago
Services
Share
Amazon EC2 R9g and R9gd memory optimized instances are now available
about 11 hours ago
Services
Share
AWS Lambda recursive loop detection is now available in all commercial AWS Regions
about 12 hours ago
Services
Share