AWS Cognito JWT Auth Policy
Authenticate requests with JWT tokens issued by AWS Cognito. This is a customized version of the OpenId JWT Policy specifically for AWS Cognito.
See this document for more information about OAuth authorization in Zuplo.
Configuration
The configuration shows how to configure the policy in the 'policies.json' document.
Code
Policy Configuration
name<string>- The name of your policy instance. This is used as a reference in your routes.policyType<string>- The identifier of the policy. This is used by the Zuplo UI. Value should becognito-jwt-auth-inbound.handler.export<string>- The name of the exported type. Value should beCognitoJwtInboundPolicy.handler.module<string>- The module containing the policy. Value should be$import(@zuplo/runtime).handler.options<object>- The options for this policy. See Policy Options below.
Policy Options
The options for this policy are specified below. All properties are optional unless specifically marked as required.
region(required)<string>- The AWS region where your Cognito instance is deployed.userPoolId(required)<string>- The user pool identifier.allowUnauthenticatedRequests<boolean>- Allow unauthenticated requests to proceed. This is use useful if you want to use multiple authentication policies or if you want to allow both authenticated and non-authenticated traffic. Defaults tofalse.oAuthResourceMetadataEnabled<boolean>- Enables OAuth 2.0 Protected Resource Metadata discovery (RFC 9728). Whentrue, requests without a bearer token receive a 401 whoseWWW-Authenticateheader pointsresource_metadataat the/.well-known/oauth-protected-resourcedocument for the request path and, when theOAuthProtectedResourcePlugindeclaresscopesSupported, lists those scopes inscope. Requires theOAuthProtectedResourcePlugininzuplo.runtime.tsor a user-defined route at that path. Defaults tofalse.
Using the Policy
OAuth 2.0 Protected Resource Metadata
The Cognito JWT Auth policy supports OAuth protected resource metadata
discovery. To enable this feature, set the oAuthResourceMetadataEnabled option
to true and add the
OAuthProtectedResourcePlugin to modules/zuplo.runtime.ts.
When configured, this enables OAuth clients to find metadata information about
how to interact with your OAuth 2.0 protected resources according to
RFC 9728.
When the plugin is configured with scopesSupported, the 401 response also
lists those scopes in the scope parameter of its WWW-Authenticate header, so
MCP clients request exactly the scopes your resource expects instead of every
scope the authorization server advertises.
See this document for more information about OAuth authorization in Zuplo.
Read more about how policies work