@aws-sdk/client-cognito-identity-provider
Version:
AWS SDK for JavaScript Cognito Identity Provider Client for Node.js, Browser and React Native
1,269 lines • 66.4 kB
TypeScript
import type { DocumentType as __DocumentType } from "@smithy/types";
import type { DeletionProtectionType, DeviceRememberedStatusType, ExplicitAuthFlowsType, FeedbackValueType, OAuthFlowType, PreventUserExistenceErrorTypes, TermsEnforcementType, TermsSourceType, UpdateReplicaStatusType, UserPoolMfaType, UserPoolTierType, VerifiedAttributeType, VerifySoftwareTokenResponseType } from "./enums";
import type { AccountRecoverySettingType, AdminCreateUserConfigType, AnalyticsConfigurationType, AssetType, AttributeType, CodeDeliveryDetailsType, CustomDomainConfigType, DeviceConfigurationType, EmailConfigurationType, GroupType, IdentityProviderType, IssuerConfigurationType, KeyConfigurationType, LambdaConfigType, ManagedLoginBrandingType, RefreshTokenRotationType, ResourceServerScopeType, ResourceServerType, RoutingType, SmsConfigurationType, TermsType, TokenValidityUnitsType, UserAttributeUpdateSettingsType, UserPoolAddOnsType, UserPoolClientType, UserPoolPolicyType, UserPoolReplicaType, VerificationMessageTemplateType } from "./models_0";
/**
* @public
*/
export interface UntagResourceResponse {
}
/**
* @public
*/
export interface UpdateAuthEventFeedbackRequest {
/**
* <p>The ID of the user pool where you want to update auth event feedback.</p>
* @public
*/
UserPoolId: string | undefined;
/**
* <p>The name of the user that you want to query or modify. The value of this parameter
* is typically your user's username, but it can be any of their alias attributes. If
* <code>username</code> isn't an alias attribute in your user pool, this value
* must be the <code>sub</code> of a local user or the username of a user from a
* third-party IdP.</p>
* @public
*/
Username: string | undefined;
/**
* <p>The ID of the authentication event that you want to submit feedback for.</p>
* @public
*/
EventId: string | undefined;
/**
* <p>The feedback token, an encrypted object generated by Amazon Cognito and passed to your user in
* the notification email message from the event.</p>
* @public
*/
FeedbackToken: string | undefined;
/**
* <p>Your feedback to the authentication event. When you provide a <code>FeedbackValue</code>
* value of <code>valid</code>, you tell Amazon Cognito that you trust a user session where Amazon Cognito
* has evaluated some level of risk. When you provide a <code>FeedbackValue</code> value of
* <code>invalid</code>, you tell Amazon Cognito that you don't trust a user session, or you
* don't believe that Amazon Cognito evaluated a high-enough risk level.</p>
* @public
*/
FeedbackValue: FeedbackValueType | undefined;
}
/**
* @public
*/
export interface UpdateAuthEventFeedbackResponse {
}
/**
* <p>Represents the request to update the device status.</p>
* @public
*/
export interface UpdateDeviceStatusRequest {
/**
* <p>A valid access token that Amazon Cognito issued to the currently signed-in user. Must include a scope claim for
* <code>aws.cognito.signin.user.admin</code>.</p>
* @public
*/
AccessToken: string | undefined;
/**
* <p>The device key of the device you want to update, for example
* <code>us-west-2_a1b2c3d4-5678-90ab-cdef-EXAMPLE11111</code>.</p>
* @public
*/
DeviceKey: string | undefined;
/**
* <p>To enable device authentication with the specified device, set to
* <code>remembered</code>.To disable, set to <code>not_remembered</code>.</p>
* @public
*/
DeviceRememberedStatus?: DeviceRememberedStatusType | undefined;
}
/**
* <p>The response to the request to update the device status.</p>
* @public
*/
export interface UpdateDeviceStatusResponse {
}
/**
* @public
*/
export interface UpdateGroupRequest {
/**
* <p>The name of the group that you want to update.</p>
* @public
*/
GroupName: string | undefined;
/**
* <p>The ID of the user pool that contains the group you want to update.</p>
* @public
*/
UserPoolId: string | undefined;
/**
* <p>A new description of the existing group.</p>
* @public
*/
Description?: string | undefined;
/**
* <p>The Amazon Resource Name (ARN) of an IAM role that you want to associate with the
* group. The role assignment contributes to the <code>cognito:roles</code> and
* <code>cognito:preferred_role</code> claims in group members' tokens.</p>
* @public
*/
RoleArn?: string | undefined;
/**
* <p>A non-negative integer value that specifies the precedence of this group relative to
* the other groups that a user can belong to in the user pool. Zero is the highest
* precedence value. Groups with lower <code>Precedence</code> values take precedence over
* groups with higher or null <code>Precedence</code> values. If a user belongs to two or
* more groups, it is the group with the lowest precedence value whose role ARN is given in
* the user's tokens for the <code>cognito:roles</code> and
* <code>cognito:preferred_role</code> claims.</p>
* <p>Two groups can have the same <code>Precedence</code> value. If this happens, neither
* group takes precedence over the other. If two groups with the same
* <code>Precedence</code> have the same role ARN, that role is used in the
* <code>cognito:preferred_role</code> claim in tokens for users in each group. If the
* two groups have different role ARNs, the <code>cognito:preferred_role</code> claim isn't
* set in users' tokens.</p>
* <p>The default <code>Precedence</code> value is null. The maximum <code>Precedence</code>
* value is <code>2^31-1</code>.</p>
* @public
*/
Precedence?: number | undefined;
}
/**
* @public
*/
export interface UpdateGroupResponse {
/**
* <p>Contains the updated details of the group, including precedence, IAM role, and
* description.</p>
* @public
*/
Group?: GroupType | undefined;
}
/**
* @public
*/
export interface UpdateIdentityProviderRequest {
/**
* <p>The Id of the user pool where you want to update your IdP.</p>
* @public
*/
UserPoolId: string | undefined;
/**
* <p>The name of the IdP that you want to update. You can pass the identity provider name
* in the <code>identity_provider</code> query parameter of requests to the <a href="https://docs.aws.amazon.com/cognito/latest/developerguide/authorization-endpoint.html">Authorize endpoint</a> to silently redirect to sign-in with the associated
* IdP.</p>
* @public
*/
ProviderName: string | undefined;
/**
* <p>The scopes, URLs, and identifiers for your external identity provider. The following
* examples describe the provider detail keys for each IdP type. These values and their
* schema are subject to change. Social IdP <code>authorize_scopes</code> values must match
* the values listed here.</p>
* <dl>
* <dt>OpenID Connect (OIDC)</dt>
* <dd>
* <p>Amazon Cognito accepts the following elements when it can't discover endpoint
* URLs from <code>oidc_issuer</code>: <code>attributes_url</code>,
* <code>authorize_url</code>, <code>jwks_uri</code>,
* <code>token_url</code>.</p>
* <p>Create or update request: <code>"ProviderDetails": \{
* "attributes_request_method": "GET", "attributes_url":
* "https://auth.example.com/userInfo", "authorize_scopes": "openid profile
* email", "authorize_url": "https://auth.example.com/authorize",
* "client_id": "1example23456789", "client_secret":
* "provider-app-client-secret", "jwks_uri":
* "https://auth.example.com/.well-known/jwks.json", "oidc_issuer":
* "https://auth.example.com", "token_url": "https://example.com/token"
* \}</code>
* </p>
* <p>Describe response: <code>"ProviderDetails": \{ "attributes_request_method":
* "GET", "attributes_url": "https://auth.example.com/userInfo",
* "attributes_url_add_attributes": "false", "authorize_scopes": "openid
* profile email", "authorize_url": "https://auth.example.com/authorize",
* "client_id": "1example23456789", "client_secret":
* "provider-app-client-secret", "jwks_uri":
* "https://auth.example.com/.well-known/jwks.json", "oidc_issuer":
* "https://auth.example.com", "token_url": "https://example.com/token"
* \}</code>
* </p>
* </dd>
* <dt>SAML</dt>
* <dd>
* <p>Create or update request with Metadata URL: <code>"ProviderDetails": \{ "IDPInit": "true",
* "IDPSignout": "true", "EncryptedResponses" : "true", "MetadataURL":
* "https://auth.example.com/sso/saml/metadata", "RequestSigningAlgorithm":
* "rsa-sha256" \}</code>
* </p>
* <p>Create or update request with Metadata file: <code>"ProviderDetails": \{ "IDPInit": "true",
* "IDPSignout": "true", "EncryptedResponses" : "true",
* "MetadataFile": "[metadata XML]", "RequestSigningAlgorithm":
* "rsa-sha256" \}</code>
* </p>
* <p>The value of <code>MetadataFile</code> must be the plaintext metadata document with all
* quote (") characters escaped by backslashes.</p>
* <p>Describe response: <code>"ProviderDetails": \{ "IDPInit": "true",
* "IDPSignout": "true", "EncryptedResponses" : "true", "ActiveEncryptionCertificate": "[certificate]",
* "MetadataURL": "https://auth.example.com/sso/saml/metadata", "RequestSigningAlgorithm":
* "rsa-sha256", "SLORedirectBindingURI":
* "https://auth.example.com/slo/saml", "SSORedirectBindingURI":
* "https://auth.example.com/sso/saml" \}</code>
* </p>
* </dd>
* <dt>LoginWithAmazon</dt>
* <dd>
* <p>Create or update request: <code>"ProviderDetails": \{ "authorize_scopes":
* "profile postal_code", "client_id":
* "amzn1.application-oa2-client.1example23456789", "client_secret":
* "provider-app-client-secret"</code>
* </p>
* <p>Describe response: <code>"ProviderDetails": \{ "attributes_url":
* "https://api.amazon.com/user/profile", "attributes_url_add_attributes":
* "false", "authorize_scopes": "profile postal_code", "authorize_url":
* "https://www.amazon.com/ap/oa", "client_id":
* "amzn1.application-oa2-client.1example23456789", "client_secret":
* "provider-app-client-secret", "token_request_method": "POST",
* "token_url": "https://api.amazon.com/auth/o2/token" \}</code>
* </p>
* </dd>
* <dt>Google</dt>
* <dd>
* <p>Create or update request: <code>"ProviderDetails": \{ "authorize_scopes":
* "email profile openid", "client_id":
* "1example23456789.apps.googleusercontent.com", "client_secret":
* "provider-app-client-secret" \}</code>
* </p>
* <p>Describe response: <code>"ProviderDetails": \{ "attributes_url":
* "https://people.googleapis.com/v1/people/me?personFields=",
* "attributes_url_add_attributes": "true", "authorize_scopes": "email
* profile openid", "authorize_url":
* "https://accounts.google.com/o/oauth2/v2/auth", "client_id":
* "1example23456789.apps.googleusercontent.com", "client_secret":
* "provider-app-client-secret", "oidc_issuer":
* "https://accounts.google.com", "token_request_method": "POST",
* "token_url": "https://www.googleapis.com/oauth2/v4/token"
* \}</code>
* </p>
* </dd>
* <dt>SignInWithApple</dt>
* <dd>
* <p>Create or update request: <code>"ProviderDetails": \{ "authorize_scopes":
* "email name", "client_id": "com.example.cognito", "private_key": "1EXAMPLE",
* "key_id": "2EXAMPLE", "team_id": "3EXAMPLE" \}</code>
* </p>
* <p>Describe response: <code>"ProviderDetails": \{
* "attributes_url_add_attributes": "false", "authorize_scopes": "email
* name", "authorize_url": "https://appleid.apple.com/auth/authorize",
* "client_id": "com.example.cognito", "key_id": "1EXAMPLE", "oidc_issuer":
* "https://appleid.apple.com", "team_id": "2EXAMPLE",
* "token_request_method": "POST", "token_url":
* "https://appleid.apple.com/auth/token" \}</code>
* </p>
* </dd>
* <dt>Facebook</dt>
* <dd>
* <p>Create or update request: <code>"ProviderDetails": \{ "api_version": "v17.0",
* "authorize_scopes": "public_profile, email", "client_id": "1example23456789",
* "client_secret": "provider-app-client-secret" \}</code>
* </p>
* <p>Describe response: <code>"ProviderDetails":
* \{ "api_version": "v17.0", "attributes_url": "https://graph.facebook.com/v17.0/me?fields=",
* "attributes_url_add_attributes": "true", "authorize_scopes": "public_profile, email",
* "authorize_url": "https://www.facebook.com/v17.0/dialog/oauth", "client_id":
* "1example23456789", "client_secret": "provider-app-client-secret", "token_request_method":
* "GET", "token_url": "https://graph.facebook.com/v17.0/oauth/access_token" \}</code>
* </p>
* </dd>
* </dl>
* @public
*/
ProviderDetails?: Record<string, string> | undefined;
/**
* <p>A mapping of IdP attributes to standard and custom user pool attributes. Specify a
* user pool attribute as the key of the key-value pair, and the IdP attribute claim name
* as the value.</p>
* @public
*/
AttributeMapping?: Record<string, string> | undefined;
/**
* <p>An array of IdP identifiers, for example <code>"IdPIdentifiers": [ "MyIdP", "MyIdP2"
* ]</code>. Identifiers are friendly names that you can pass in the
* <code>idp_identifier</code> query parameter of requests to the <a href="https://docs.aws.amazon.com/cognito/latest/developerguide/authorization-endpoint.html">Authorize endpoint</a> to silently redirect to sign-in with the associated IdP.
* Identifiers in a domain format also enable the use of <a href="https://docs.aws.amazon.com/cognito/latest/developerguide/cognito-user-pools-managing-saml-idp-naming.html">email-address matching with SAML providers</a>. </p>
* @public
*/
IdpIdentifiers?: string[] | undefined;
}
/**
* @public
*/
export interface UpdateIdentityProviderResponse {
/**
* <p>The identity provider details.</p>
* @public
*/
IdentityProvider: IdentityProviderType | undefined;
}
/**
* @public
*/
export interface UpdateManagedLoginBrandingRequest {
/**
* <p>The ID of the user pool that contains the managed login branding style that you want
* to update.</p>
* @public
*/
UserPoolId?: string | undefined;
/**
* <p>The ID of the managed login branding style that you want to update.</p>
* @public
*/
ManagedLoginBrandingId?: string | undefined;
/**
* <p>When <code>true</code>, applies the default branding style options. This option
* reverts to default style options that are managed by Amazon Cognito. You can modify them later in
* the branding editor.</p>
* <p>When you specify <code>true</code> for this option, you must also omit values for
* <code>Settings</code> and <code>Assets</code> in the request.</p>
* @public
*/
UseCognitoProvidedValues?: boolean | undefined;
/**
* <p>A JSON file, encoded as a <code>Document</code> type, with the the settings that you
* want to apply to your style.</p>
* <p>The following components are not currently implemented and reserved for future
* use:</p>
* <ul>
* <li>
* <p>
* <code>signUp</code>
* </p>
* </li>
* <li>
* <p>
* <code>instructions</code>
* </p>
* </li>
* <li>
* <p>
* <code>sessionTimerDisplay</code>
* </p>
* </li>
* <li>
* <p>
* <code>languageSelector</code> (for localization, see <a href="https://docs.aws.amazon.com/cognito/latest/developerguide/cognito-user-pools-managed-login.html#managed-login-localization">Managed login localization)</a>
* </p>
* </li>
* </ul>
* @public
*/
Settings?: __DocumentType | undefined;
/**
* <p>An array of image files that you want to apply to roles like backgrounds, logos, and
* icons. Each object must also indicate whether it is for dark mode, light mode, or
* browser-adaptive mode.</p>
* @public
*/
Assets?: AssetType[] | undefined;
}
/**
* @public
*/
export interface UpdateManagedLoginBrandingResponse {
/**
* <p>The details of the branding style that you updated.</p>
* @public
*/
ManagedLoginBranding?: ManagedLoginBrandingType | undefined;
}
/**
* @public
*/
export interface UpdateResourceServerRequest {
/**
* <p>The ID of the user pool that contains the resource server that you want to
* update.</p>
* @public
*/
UserPoolId: string | undefined;
/**
* <p>A unique resource server identifier for the resource server. The identifier can be an
* API friendly name like <code>solar-system-data</code>. You can also set an API URL like
* <code>https://solar-system-data-api.example.com</code> as your identifier.</p>
* <p>Amazon Cognito represents scopes in the access token in the format
* <code>$resource-server-identifier/$scope</code>. Longer scope-identifier strings
* increase the size of your access tokens.</p>
* @public
*/
Identifier: string | undefined;
/**
* <p>The updated name of the resource server.</p>
* @public
*/
Name: string | undefined;
/**
* <p>An array of updated custom scope names and descriptions that you want to associate
* with your resource server.</p>
* @public
*/
Scopes?: ResourceServerScopeType[] | undefined;
}
/**
* @public
*/
export interface UpdateResourceServerResponse {
/**
* <p>The updated details of the requested resource server.</p>
* @public
*/
ResourceServer: ResourceServerType | undefined;
}
/**
* @public
*/
export interface UpdateTermsRequest {
/**
* <p>The ID of the terms document that you want to update.</p>
* @public
*/
TermsId: string | undefined;
/**
* <p>The ID of the user pool that contains the terms that you want to update.</p>
* @public
*/
UserPoolId: string | undefined;
/**
* <p>The new name that you want to apply to the requested terms documents.</p>
* @public
*/
TermsName?: string | undefined;
/**
* <p>This parameter is reserved for future use and currently accepts only one value.</p>
* @public
*/
TermsSource?: TermsSourceType | undefined;
/**
* <p>This parameter is reserved for future use and currently accepts only one value.</p>
* @public
*/
Enforcement?: TermsEnforcementType | undefined;
/**
* <p>A map of URLs to languages. For each localized language that will view the requested
* <code>TermsName</code>, assign a URL. A selection of <code>cognito:default</code>
* displays for all languages that don't have a language-specific URL.</p>
* <p>For example, <code>"cognito:default": "https://terms.example.com", "cognito:spanish":
* "https://terms.example.com/es"</code>.</p>
* @public
*/
Links?: Record<string, string> | undefined;
}
/**
* @public
*/
export interface UpdateTermsResponse {
/**
* <p>A summary of the updates to your terms documents.</p>
* @public
*/
Terms?: TermsType | undefined;
}
/**
* <p>Represents the request to update user attributes.</p>
* @public
*/
export interface UpdateUserAttributesRequest {
/**
* <p>An array of name-value pairs representing user attributes.</p>
* <p>For custom attributes, you must add a <code>custom:</code> prefix to the attribute
* name.</p>
* <p>If you have set an attribute to require verification before Amazon Cognito updates its value,
* this request doesn’t immediately update the value of that attribute. After your user
* receives and responds to a verification message to verify the new value, Amazon Cognito updates
* the attribute value. Your user can sign in and receive messages with the original
* attribute value until they verify the new value.</p>
* @public
*/
UserAttributes: AttributeType[] | undefined;
/**
* <p>A valid access token that Amazon Cognito issued to the currently signed-in user. Must include a scope claim for
* <code>aws.cognito.signin.user.admin</code>.</p>
* @public
*/
AccessToken: string | undefined;
/**
* <p>A map of custom key-value pairs that you can provide as input for any custom workflows
* that this action triggers. You create custom workflows by assigning Lambda functions
* to user pool triggers.</p>
* <p>When Amazon Cognito invokes any of these functions, it passes a JSON payload, which the
* function receives as input. This payload contains a <code>clientMetadata</code>
* attribute that provides the data that you assigned to the ClientMetadata parameter in
* your request. In your function code, you can process the <code>clientMetadata</code>
* value to enhance your workflow for your specific needs.</p>
* <p>To review the Lambda trigger types that Amazon Cognito invokes at runtime with API requests, see <a href="https://docs.aws.amazon.com/cognito/latest/developerguide/cognito-user-pools-working-with-lambda-triggers.html#lambda-triggers-by-event">
* Connecting API actions to Lambda triggers</a> in the <i>Amazon Cognito Developer Guide</i>.</p>
* <note>
* <p>When you use the <code>ClientMetadata</code> parameter, note that Amazon Cognito won't do the
* following:</p>
* <ul>
* <li>
* <p>Store the <code>ClientMetadata</code> value. This data is available only
* to Lambda triggers that are assigned to a user pool to support custom
* workflows. If your user pool configuration doesn't include triggers, the
* <code>ClientMetadata</code> parameter serves no purpose.</p>
* </li>
* <li>
* <p>Validate the <code>ClientMetadata</code> value.</p>
* </li>
* <li>
* <p>Encrypt the <code>ClientMetadata</code> value. Don't send sensitive
* information in this parameter.</p>
* </li>
* </ul>
* </note>
* @public
*/
ClientMetadata?: Record<string, string> | undefined;
}
/**
* <p>Represents the response from the server for the request to update user
* attributes.</p>
* @public
*/
export interface UpdateUserAttributesResponse {
/**
* <p>When the attribute-update request includes an email address or phone number attribute,
* Amazon Cognito sends a message to users with a code that confirms ownership of the new value that
* they entered. The <code>CodeDeliveryDetails</code> object is information about the
* delivery destination for that link or code. This behavior happens in user pools
* configured to automatically verify changes to those attributes. For more information,
* see <a href="https://docs.aws.amazon.com/cognito/latest/developerguide/signing-up-users-in-your-app.html#verifying-when-users-change-their-email-or-phone-number">Verifying when users change their email or phone
* number</a>.</p>
* @public
*/
CodeDeliveryDetailsList?: CodeDeliveryDetailsType[] | undefined;
}
/**
* <p>Represents the request to update the user pool.</p>
* @public
*/
export interface UpdateUserPoolRequest {
/**
* <p>The ID of the user pool you want to update.</p>
* @public
*/
UserPoolId: string | undefined;
/**
* <p>The password policy and sign-in policy in the user pool. The password policy sets
* options like password complexity requirements and password history. The sign-in policy
* sets the options available to applications in <a href="https://docs.aws.amazon.com/cognito/latest/developerguide/authentication-flows-selection-sdk.html#authentication-flows-selection-choice">choice-based authentication</a>.</p>
* @public
*/
Policies?: UserPoolPolicyType | undefined;
/**
* <p>When active, <code>DeletionProtection</code> prevents accidental deletion of your user
* pool. Before you can delete a user pool that you have protected against deletion, you
* must deactivate this feature.</p>
* <p>When you try to delete a protected user pool in a <code>DeleteUserPool</code> API request,
* Amazon Cognito returns an <code>InvalidParameterException</code> error. To delete a protected user pool,
* send a new <code>DeleteUserPool</code> request after you deactivate deletion protection in an
* <code>UpdateUserPool</code> API request.</p>
* @public
*/
DeletionProtection?: DeletionProtectionType | undefined;
/**
* <p>A collection of user pool Lambda triggers. Amazon Cognito invokes triggers at several possible
* stages of authentication operations. Triggers can modify the outcome of the operations
* that invoked them.</p>
* @public
*/
LambdaConfig?: LambdaConfigType | undefined;
/**
* <p>The attributes that you want your user pool to automatically verify. Possible values:
* <b>email</b>, <b>phone_number</b>. For more information see <a href="https://docs.aws.amazon.com/cognito/latest/developerguide/signing-up-users-in-your-app.html#allowing-users-to-sign-up-and-confirm-themselves">Verifying contact information at sign-up</a>.</p>
* @public
*/
AutoVerifiedAttributes?: VerifiedAttributeType[] | undefined;
/**
* <p>This parameter is no longer used.</p>
* @public
*/
SmsVerificationMessage?: string | undefined;
/**
* <p>This parameter is no longer used.</p>
* @public
*/
EmailVerificationMessage?: string | undefined;
/**
* <p>This parameter is no longer used.</p>
* @public
*/
EmailVerificationSubject?: string | undefined;
/**
* <p>The template for the verification message that your user pool delivers to users who
* set an email address or phone number attribute.</p>
* <p>Set the email message type that corresponds to your <code>DefaultEmailOption</code>
* selection. For <code>CONFIRM_WITH_LINK</code>, specify an
* <code>EmailMessageByLink</code> and leave <code>EmailMessage</code> blank. For
* <code>CONFIRM_WITH_CODE</code>, specify an <code>EmailMessage</code> and leave
* <code>EmailMessageByLink</code> blank. When you supply both parameters with either
* choice, Amazon Cognito returns an error.</p>
* @public
*/
VerificationMessageTemplate?: VerificationMessageTemplateType | undefined;
/**
* <p>The contents of the SMS message that your user pool sends to users in SMS
* authentication.</p>
* @public
*/
SmsAuthenticationMessage?: string | undefined;
/**
* <p>The settings for updates to user attributes. These settings include the property <code>AttributesRequireVerificationBeforeUpdate</code>,
* a user-pool setting that tells Amazon Cognito how to handle changes to the value of your users' email address and phone number attributes. For
* more information, see <a href="https://docs.aws.amazon.com/cognito/latest/developerguide/user-pool-settings-email-phone-verification.html#user-pool-settings-verifications-verify-attribute-updates">
* Verifying updates to email addresses and phone numbers</a>.</p>
* @public
*/
UserAttributeUpdateSettings?: UserAttributeUpdateSettingsType | undefined;
/**
* <p>Sets multi-factor authentication (MFA) to be on, off, or optional. When
* <code>ON</code>, all users must set up MFA before they can sign in. When
* <code>OPTIONAL</code>, your application must make a client-side determination of
* whether a user wants to register an MFA device. For user pools with adaptive
* authentication with threat protection, choose <code>OPTIONAL</code>.</p>
* <p>When <code>MfaConfiguration</code> is <code>OPTIONAL</code>, managed login
* doesn't automatically prompt users to set up MFA. Amazon Cognito generates MFA prompts in
* API responses and in managed login for users who have chosen and configured a preferred
* MFA factor.</p>
* @public
*/
MfaConfiguration?: UserPoolMfaType | undefined;
/**
* <p>The device-remembering configuration for a user pool. Device remembering or device
* tracking is a "Remember me on this device" option for user pools that perform
* authentication with the device key of a trusted device in the back end, instead of a
* user-provided MFA code. For more information about device authentication, see <a href="https://docs.aws.amazon.com/cognito/latest/developerguide/amazon-cognito-user-pools-device-tracking.html">Working with user devices in your user pool</a>. A null value indicates that
* you have deactivated device remembering in your user pool.</p>
* <note>
* <p>When you provide a value for any <code>DeviceConfiguration</code> field, you
* activate the Amazon Cognito device-remembering feature. For more information, see <a href="https://docs.aws.amazon.com/cognito/latest/developerguide/amazon-cognito-user-pools-device-tracking.html">Working with devices</a>.</p>
* </note>
* @public
*/
DeviceConfiguration?: DeviceConfigurationType | undefined;
/**
* <p>The email configuration of your user pool. The email configuration type sets your
* preferred sending method, Amazon Web Services Region, and sender for email invitation and verification
* messages from your user pool.</p>
* @public
*/
EmailConfiguration?: EmailConfigurationType | undefined;
/**
* <p>The SMS configuration with the settings for your Amazon Cognito user pool to send SMS message
* with Amazon Simple Notification Service. To send SMS messages with Amazon SNS in the Amazon Web Services Region that you want, the
* Amazon Cognito user pool uses an Identity and Access Management (IAM) role in your Amazon Web Services account. For
* more information see <a href="https://docs.aws.amazon.com/cognito/latest/developerguide/user-pool-sms-settings.html">SMS message settings</a>.</p>
* @public
*/
SmsConfiguration?: SmsConfigurationType | undefined;
/**
* <p>The tag keys and values to assign to the user pool. A tag is a label that you can use
* to categorize and manage user pools in different ways, such as by purpose, owner,
* environment, or other criteria.</p>
* @public
*/
UserPoolTags?: Record<string, string> | undefined;
/**
* <p>The configuration for administrative creation of users. Includes the template for the
* invitation message for new users, the duration of temporary passwords, and permitting
* self-service sign-up.</p>
* @public
*/
AdminCreateUserConfig?: AdminCreateUserConfigType | undefined;
/**
* <p>Contains settings for activation of threat protection, including the operating
* mode and additional authentication types. To log user security information but take
* no action, set to <code>AUDIT</code>. To configure automatic security responses to
* potentially unwanted traffic to your user pool, set to <code>ENFORCED</code>.</p>
* <p>For more information, see <a href="https://docs.aws.amazon.com/cognito/latest/developerguide/cognito-user-pool-settings-advanced-security.html">Adding advanced security to a user pool</a>. To activate this setting, your user pool must be on the <a href="https://docs.aws.amazon.com/cognito/latest/developerguide/feature-plans-features-plus.html">
* Plus tier</a>.</p>
* @public
*/
UserPoolAddOns?: UserPoolAddOnsType | undefined;
/**
* <p>The available verified method a user can use to recover their password when they call
* <code>ForgotPassword</code>. You can use this setting to define a preferred method
* when a user has more than one method available. With this setting, SMS doesn't qualify
* for a valid password recovery mechanism if the user also has SMS multi-factor
* authentication (MFA) activated. In the absence of this setting, Amazon Cognito uses the legacy
* behavior to determine the recovery method where SMS is preferred through email.</p>
* @public
*/
AccountRecoverySetting?: AccountRecoverySettingType | undefined;
/**
* <p>The updated name of your user pool.</p>
* @public
*/
PoolName?: string | undefined;
/**
* <p>The user pool <a href="https://docs.aws.amazon.com/cognito/latest/developerguide/cognito-sign-in-feature-plans.html">feature plan</a>, or tier. This parameter determines the
* eligibility of the user pool for features like managed login, access-token
* customization, and threat protection. Defaults to <code>ESSENTIALS</code>.</p>
* @public
*/
UserPoolTier?: UserPoolTierType | undefined;
/**
* <p>The key configuration for the user pool. In secondary regions, this parameter must
* match the existing configuration and cannot be modified.</p>
* @public
*/
KeyConfiguration?: KeyConfigurationType | undefined;
/**
* <p>The issuer configuration for the user pool. In secondary regions, this parameter must
* match the existing configuration and cannot be modified.</p>
* @public
*/
IssuerConfiguration?: IssuerConfigurationType | undefined;
}
/**
* <p>Represents the response from the server when you make a request to update the user
* pool.</p>
* @public
*/
export interface UpdateUserPoolResponse {
}
/**
* <p>Represents the request to update the user pool client.</p>
* @public
*/
export interface UpdateUserPoolClientRequest {
/**
* <p>The ID of the user pool where you want to update the app client.</p>
* @public
*/
UserPoolId: string | undefined;
/**
* <p>The ID of the app client that you want to update.</p>
* @public
*/
ClientId: string | undefined;
/**
* <p>A friendly name for the app client.</p>
* @public
*/
ClientName?: string | undefined;
/**
* <p>The refresh token time limit. After this limit expires, your user can't use
* their refresh token. To specify the time unit for <code>RefreshTokenValidity</code> as
* <code>seconds</code>, <code>minutes</code>, <code>hours</code>, or <code>days</code>,
* set a <code>TokenValidityUnits</code> value in your API request.</p>
* <p>For example, when you set <code>RefreshTokenValidity</code> as <code>10</code> and
* <code>TokenValidityUnits</code> as <code>days</code>, your user can refresh their session
* and retrieve new access and ID tokens for 10 days.</p>
* <p>The default time unit for <code>RefreshTokenValidity</code> in an API request is days.
* You can't set <code>RefreshTokenValidity</code> to 0. If you do, Amazon Cognito overrides the
* value with the default value of 30 days. <i>Valid range</i> is displayed below
* in seconds.</p>
* <p>If you don't specify otherwise in the configuration of your app client, your refresh
* tokens are valid for 30 days.</p>
* @public
*/
RefreshTokenValidity?: number | undefined;
/**
* <p>The access token time limit. After this limit expires, your user can't use
* their access token. To specify the time unit for <code>AccessTokenValidity</code> as
* <code>seconds</code>, <code>minutes</code>, <code>hours</code>, or <code>days</code>,
* set a <code>TokenValidityUnits</code> value in your API request.</p>
* <p>For example, when you set <code>AccessTokenValidity</code> to <code>10</code> and
* <code>TokenValidityUnits</code> to <code>hours</code>, your user can authorize access with
* their access token for 10 hours.</p>
* <p>The default time unit for <code>AccessTokenValidity</code> in an API request is hours.
* <i>Valid range</i> is displayed below in seconds.</p>
* <p>If you don't specify otherwise in the configuration of your app client, your access
* tokens are valid for one hour.</p>
* @public
*/
AccessTokenValidity?: number | undefined;
/**
* <p>The ID token time limit. After this limit expires, your user can't use
* their ID token. To specify the time unit for <code>IdTokenValidity</code> as
* <code>seconds</code>, <code>minutes</code>, <code>hours</code>, or <code>days</code>,
* set a <code>TokenValidityUnits</code> value in your API request.</p>
* <p>For example, when you set <code>IdTokenValidity</code> as <code>10</code> and
* <code>TokenValidityUnits</code> as <code>hours</code>, your user can authenticate their
* session with their ID token for 10 hours.</p>
* <p>The default time unit for <code>IdTokenValidity</code> in an API request is hours.
* <i>Valid range</i> is displayed below in seconds.</p>
* <p>If you don't specify otherwise in the configuration of your app client, your ID
* tokens are valid for one hour.</p>
* @public
*/
IdTokenValidity?: number | undefined;
/**
* <p>The units that validity times are represented in. The default unit for refresh tokens
* is days, and the default for ID and access tokens are hours.</p>
* @public
*/
TokenValidityUnits?: TokenValidityUnitsType | undefined;
/**
* <p>The list of user attributes that you want your app client to have read access to.
* After your user authenticates in your app, their access token authorizes them to read
* their own attribute value for any attribute in this list.</p>
* <p>When you don't specify the <code>ReadAttributes</code> for your app client, your
* app can read the values of <code>email_verified</code>,
* <code>phone_number_verified</code>, and the standard attributes of your user pool.
* When your user pool app client has read access to these default attributes,
* <code>ReadAttributes</code> doesn't return any information. Amazon Cognito only
* populates <code>ReadAttributes</code> in the API response if you have specified your own
* custom set of read attributes.</p>
* @public
*/
ReadAttributes?: string[] | undefined;
/**
* <p>The list of user attributes that you want your app client to have write access to.
* After your user authenticates in your app, their access token authorizes them to set or
* modify their own attribute value for any attribute in this list.</p>
* <p>When you don't specify the <code>WriteAttributes</code> for your app client, your
* app can write the values of the Standard attributes of your user pool. When your user
* pool has write access to these default attributes, <code>WriteAttributes</code>
* doesn't return any information. Amazon Cognito only populates
* <code>WriteAttributes</code> in the API response if you have specified your own
* custom set of write attributes.</p>
* <p>If your app client allows users to sign in through an IdP, this array must include all
* attributes that you have mapped to IdP attributes. Amazon Cognito updates mapped attributes when
* users sign in to your application through an IdP. If your app client does not have write
* access to a mapped attribute, Amazon Cognito throws an error when it tries to update the
* attribute. For more information, see <a href="https://docs.aws.amazon.com/cognito/latest/developerguide/cognito-user-pools-specifying-attribute-mapping.html">Specifying IdP Attribute Mappings for Your user
* pool</a>.</p>
* @public
*/
WriteAttributes?: string[] | undefined;
/**
* <p>The <a href="https://docs.aws.amazon.com/cognito/latest/developerguide/amazon-cognito-user-pools-authentication-flow-methods.html">authentication flows</a> that you want your user pool client to support. For each app
* client in your user pool, you can sign in your users with any combination of one or more flows, including with
* a user name and Secure Remote Password (SRP), a user name and password, or a custom authentication process that
* you define with Lambda functions.</p>
* <note>
* <p>If you don't specify a value for <code>ExplicitAuthFlows</code>, your app client supports
* <code>ALLOW_REFRESH_TOKEN_AUTH</code>, <code>ALLOW_USER_SRP_AUTH</code>, and <code>ALLOW_CUSTOM_AUTH</code>.
* </p>
* </note>
* <p>The values for authentication flow options include the following.</p>
* <ul>
* <li>
* <p>
* <code>ALLOW_USER_AUTH</code>: Enable selection-based sign-in
* with <code>USER_AUTH</code>. This setting covers username-password,
* secure remote password (SRP), passwordless, and passkey authentication.
* This authentiation flow can do username-password and SRP authentication
* without other <code>ExplicitAuthFlows</code> permitting them. For example
* users can complete an SRP challenge through <code>USER_AUTH</code>
* without the flow <code>USER_SRP_AUTH</code> being active for the app
* client. This flow doesn't include <code>CUSTOM_AUTH</code>.
* </p>
* <p>To activate this setting, your user pool must be in the <a href="https://docs.aws.amazon.com/cognito/latest/developerguide/feature-plans-features-essentials.html">
* Essentials tier</a> or higher.</p>
* </li>
* <li>
* <p>
* <code>ALLOW_ADMIN_USER_PASSWORD_AUTH</code>: Enable admin based user password
* authentication flow <code>ADMIN_USER_PASSWORD_AUTH</code>. This setting replaces
* the <code>ADMIN_NO_SRP_AUTH</code> setting. With this authentication flow, your app
* passes a user name and password to Amazon Cognito in the request, instead of using the Secure
* Remote Password (SRP) protocol to securely transmit the password.</p>
* </li>
* <li>
* <p>
* <code>ALLOW_CUSTOM_AUTH</code>: Enable Lambda trigger based
* authentication.</p>
* </li>
* <li>
* <p>
* <code>ALLOW_USER_PASSWORD_AUTH</code>: Enable user password-based
* authentication. In this flow, Amazon Cognito receives the password in the request instead
* of using the SRP protocol to verify passwords.</p>
* </li>
* <li>
* <p>
* <code>ALLOW_USER_SRP_AUTH</code>: Enable SRP-based authentication.</p>
* </li>
* <li>
* <p>
* <code>ALLOW_REFRESH_TOKEN_AUTH</code>: Enable authflow to refresh
* tokens.</p>
* </li>
* </ul>
* <p>In some environments, you will see the values <code>ADMIN_NO_SRP_AUTH</code>, <code>CUSTOM_AUTH_FLOW_ONLY</code>, or <code>USER_PASSWORD_AUTH</code>.
* You can't assign these legacy <code>ExplicitAuthFlows</code> values to user pool clients at the same time as values that begin with <code>ALLOW_</code>,
* like <code>ALLOW_USER_SRP_AUTH</code>.</p>
* @public
*/
ExplicitAuthFlows?: ExplicitAuthFlowsType[] | undefined;
/**
* <p>A list of provider names for the identity providers (IdPs) that are supported on this
* client. The following are supported: <code>COGNITO</code>, <code>Facebook</code>,
* <code>Google</code>, <code>SignInWithApple</code>, and <code>LoginWithAmazon</code>.
* You can also specify the names that you configured for the SAML and OIDC IdPs in your
* user pool, for example <code>MySAMLIdP</code> or <code>MyOIDCIdP</code>.</p>
* <p>This parameter sets the IdPs that <a href="https://docs.aws.amazon.com/cognito/latest/developerguide/cognito-user-pools-managed-login.html">managed
* login</a> will display on the login page for your app client. The removal of
* <code>COGNITO</code> from this list doesn't prevent authentication operations
* for local users with the user pools API in an Amazon Web Services SDK. The only way to prevent
* SDK-based authentication is to block access with a <a href="https://docs.aws.amazon.com/cognito/latest/developerguide/user-pool-waf.html">WAF rule</a>.
* </p>
* @public
*/
SupportedIdentityProviders?: string[] | undefined;
/**
* <p>A list of allowed redirect, or callback, URLs for managed login authentication. These
* URLs are the paths where you want to send your users' browsers after they complete
* authentication with managed login or a third-party IdP. Typically, callback URLs are the
* home of an application that uses OAuth or OIDC libraries to process authentication
* outcomes.</p>
* <p>A redirect URI must meet the following requirements:</p>
* <ul>
* <li>
* <p>Be an absolute URI.</p>
* </li>
* <li>
* <p>Be registered with the authorization server. Amazon Cognito doesn't accept
* authorization requests with <code>redirect_uri</code> values that aren't in
* the list of <code>CallbackURLs</code> that you provide in this parameter.</p>
* </li>
* <li>
* <p>Not include a fragment component.</p>
* </li>
* </ul>
* <p>See <a href="https://tools.ietf.org/html/rfc6749#section-3.1.2">OAuth 2.0 -
* Redirection Endpoint</a>.</p>
* <p>Amazon Cognito requires HTTPS over HTTP except for http://localhost for testing purposes
* only.</p>
* <p>App callback URLs such as <code>myapp://example</code> are also supported.</p>
* @public
*/
CallbackURLs?: string[] | undefined;
/**
* <p>A list of allowed logout URLs for managed login authentication. When you pass
* <code>logout_uri</code> and <code>client_id</code> parameters to
* <code>/logout</code>, Amazon Cognito signs out your user and redirects them to the logout
* URL. This parameter describes the URLs that you want to be the permitted targets of
* <code>logout_uri</code>. A typical use of these URLs is when a user selects "Sign
* out" and you redirect them to your public homepage. For more information, see <a href="https://docs.aws.amazon.com/cognito/latest/developerguide/logout-endpoint.html">Logout
* endpoint</a>.</p>
* @public
*/
LogoutURLs?: string[] | undefined;
/**
* <p>The default redirect URI. In app clients with one assigned IdP, replaces
* <code>redirect_uri</code> in authentication requests. Must be in the
* <code>CallbackURLs</code> list.</p>
* @public
*/
DefaultRedirectURI?: string | undefined;
/**
* <p>The OAuth grant types that you want your app client to generate. To create an app
* client that generates client credentials grants, you must add
* <code>client_credentials</code> as the only allowed OAuth flow.</p>
* <dl>
* <dt>code</dt>
* <dd>
* <p>Use a code grant flow, which provides an authorization code as the
* response. This code can be exchanged for access tokens with the
* <code>/oauth2/token</code> endpoint.</p>
* </dd>
* <dt>implicit</dt>
* <dd>
* <p>Issue the access token (and, optionally, ID token, based on scopes)
* directly to your user.</p>
* </dd>
* <dt>client_credentials</dt>
* <dd>
* <p>Issue the access token from the <code>/oauth2/token</code> endpoint
* directly to a non-person user using a combination of the client ID and
* client secret.</p>
* </dd>
* </dl>
* @public
*/
AllowedOAuthFlows?: OAuthFlowType[] | undefined;
/**
* <p>The OAuth, OpenID Connect (OIDC), and custom scopes that you want to permit your app
* client to authorize access with. Scopes govern access control to user pool self-service
* API operations, user data from the <code>userInfo</code> endpoint, and third-party APIs.
* Scope values include <code>phone</code>, <code>email</code>, <code>openid</code>, and
* <code>profile</code>. The <code>aws.cognito.signin.user.admin</code> scope
* authorizes user self-service operations. Custom scopes with resource servers authorize
* access to external APIs.</p>
* @public
*/
AllowedOAuthScopes?: string[] | undefined;
/**
* <p>Set to <code>true</code> to use OAuth 2.0 authorization server features in your app client.</p>
* <p>This parameter must have a value of <code>true</code> before you can configure
* the following features in your app client.</p>
* <ul>
* <li>
* <p>
* <code>CallBackURLs</code>: Callback URLs.</p>
* </li>
* <li>
* <p>
* <code>LogoutURLs</code>: Sign-out redirect URLs.</p>
* </li>
* <li>
* <p>
* <code>AllowedOAuthScopes</code>: OAuth 2.0 scopes.</p>
* </li>
* <li>
* <p>
* <code>AllowedOAuthFlows</code>: Support for authorization code, implicit, and client credentials OAuth 2.0 grants.</p>
* </li>
* </ul>
* <p>To use authorization server features, configure one of these features in the Amazon Cognito console or set
* <code>AllowedOAuthFlowsUserPoolClient</code> to <code>true</code> in a <code>CreateUserPoolClient</code> or
* <code>UpdateUserPoolClient</code> API request. If you don't set a value for
* <code>AllowedOAuthFlowsUserPoolClient</code> in a request with the CLI or SDKs, it defaults
* to <code>false</code>. When <code>false</code>, only SDK-based API sign-in is permitted.</p>
* @public
*/
AllowedOAuthFlowsUserPoolClient?: boolean | undefined;
/**
* <p>The user pool analytics configuration for collecting metrics and sending them to your
* Amazon Pinpoint campaign.</p>
* <p>In Amazon Web Services Regions where Amazon Pinpoint isn't available, user pools might not have access to
* analytics or might be configurable with campaigns in the US East (N. Virginia) Region. For
* more information, see <a href="https://docs.aws.amazon.com/cognito/latest/developerguide/cognito-user-pools-pinpoint-integration.html">Using Amazon Pinpoint analytics</a>.</p>
* @public
*/
AnalyticsConfiguration?: AnalyticsConfigurationType | undefined;
/**
* <p>When <code>ENABLED</code>, suppresses messages that might indicate a valid user exists
* when someone attempts sign-in. This parameters sets your preference for the errors and
* responses that you want Amazon Cognito APIs to return during authentication, account
* confirmation, and password recovery when the user doesn't exist in the user pool. When
* set to <code>ENABLED</code> and the user doesn't exist, authentication returns an error
* indicating either the username or password was incorrect. Account confirmation and
* password recovery return a response indicating a code was sent to a simulated
* destination. When set to <code>LEGACY</code>, those APIs return a
* <code>UserNotFoundException</code> exception if the user doesn't exist in the user
* pool.</p>
* <p>Defaults to <code>LEGACY</code>.</p>
* @public
*/
PreventUserExistenceErrors?: PreventUserExistenceErrorTypes | undefined;
/**
* <p>Activates or deactivates <a href="https://docs.aws.amazon.com/cognito/latest/developerguide/token-revocation.html">token
* revocation</a> in the target app client.</p>
* @public
*/
EnableTokenRevocation?: boolean | undefined;
/**
* <p>When <code>true</code>, your application can include additional
* <code>UserContextData</code> in authentication requests. This data includes the IP
* address, and contributes to analysis by threat protection features. For more information
* about propagation of user context data, see <a href="https://docs.aws.amazon.com/cognito/latest/developerguide/cognito-user-pool-settings-adaptive-authentication.html#user-pool-settings-adaptive-authentication-device-fingerprint">Adding session data to API requests</a>. If you don’t include this parameter,
* you can't send the source IP address to Amazon Cognito threat protection features. You can only
* activate <code>EnablePropagateAdditionalUserContextData</code> in an app client that has
* a client secret.</p>
* @public
*/
EnablePropagateAdditionalUserContextData?: boolean | undefined;
/**
* <p>Amazon Cognito creates a session token for each API request in an authentication flow. <code>AuthSessionValidity</code> is the duration,
* in minutes, of that session token. Your user pool native user must respond to each authentication challenge before the session expires.</p>
* @public
*/
AuthSessionValidity?: number | undefined;
/**
* <p>The configuration of your app client for refresh token rotation. When enabled, your
* app client issues new ID, access, and refresh tokens when users renew their sessions
* with refresh tokens. When disabled, token refresh issues only ID and access
* tokens.</p>
* @public
*/
RefreshTokenRotation?: RefreshTokenRotationType | undefined;
}
/**
* <p>Represents the response from the server to the request to update the user pool
* client.</p>
* @public
*/
export interface UpdateUserPoolClientResponse {
/**
* <p>The updated details of your app client.</p>
* @public
*/
UserPoolClient?: UserPoolClientType | undefined;
}
/**
* <p>The UpdateUserPoolDomain request input.</p>
* @public
*/
export interface UpdateUserPoolDomainRequest {
/**
* <p>The name of the domain that you want to update. For custom domains, this is the
* fully-qualified domain name, for example <code>auth.example.com</code>. For prefix
* domains, this is the prefix alone, such as <code>myprefix</code>.</p>
* @public
*/
Domain: string | undefined;
/**
* <p>The ID of the user pool that is associated with the domain you're updating.</p>
* @public
*/
UserPoolId: string | undefined;
/**
* <p>A version number that indicates the state of managed login for your domain. Version
* <code>1</code> is hosted UI (classic). Version <code>2</code> is the newer managed
* login with the branding editor. For more information, see <a href="https://docs.aws.amazon.com/cognito/latest/developerguide/cognito-user-pools-managed-login.html">Managed login</a>.</p>
* @public
*/
ManagedLoginVersion?: number | undefined;
/**
* <p>The configuration for a custom domain that hosts managed login for your application.
* In an <code>UpdateUserPoolDomain</code> request, this parameter specifies an SSL
* certificate for the managed login hosted webserver. The certificate must be an ACM ARN
* in <code>us-east-1</code>.</p>
* <p>When you create a custom domain, the passkey RP ID defaults to the custom domain. If
* you had a prefix domain active, this will cause passkey integration for your prefix
* domain to stop working due to a mismatch in RP ID. To keep the prefix domain passkey
* integration working, you can explicitly set RP ID to the prefix domain.</p>
* @public
*/
CustomDomainConfig?: CustomDomainConfigType | undefined;
/**
* <p>The routing configuration for the user pool domain. Specifies failover settings for
* multi-region deployments.</p>
* @public
*/
Routing?: RoutingType | undefined;
}
/**
* <p>The UpdateUserPoolDomain response output.</p>
* @public
*/
export interface UpdateUserPoolDomainResponse {
/**
* <p>A version number that indicates the state of managed login for your domain. Version
* <code>1</code> is hosted UI (classic). Version <code>2</code> is the newer managed
* login with the branding editor. For more information, see <a href="https://docs.aws.amazon.com/cognito/latest/developerguide/cognito-user-pools-managed-login.html">Managed login</a>.</p>
* @public
*/
ManagedLoginVersion?: number | undefined;
/**
* <p>The fully-qualified domain name (FQDN) of the Amazon CloudFront distribution that hosts your
* managed login or classic hosted UI pages. You domain-name authority must have an alias
* record that points requests for your custom domain to this FQDN. Amazon Cognito returns this
* value if you set a custom domain with <code>CustomDomainConfig</code>. If you set an
* Amazon Cognito prefix domain, this operation returns a blank response.</p>
* @public
*/
CloudFrontDomain?: string | undefined;
/**
* <p>The updated routing configuration for the user pool domain.</p>
* @public
*/
Routing?: RoutingType | undefined;
}
/**
* @public
*/
export interface UpdateUserPoolReplicaRequest {
/**
* <p>The ID of the user pool that contains the replica to update.</p>
* @public
*/
UserPoolId: string | undefined;
/**
* <p>The Amazon Web Services Region of the replica to update.</p>
* @public
*/
RegionName: string | undefined;
/**
* <p>The status to set for the replica. Valid values are ACTIVE and INACTIVE.</p>
* @public
*/
Status: UpdateReplicaStatusType | undefined;
}
/**
* @public
*/
export interface UpdateUserPoolReplicaResponse {
/**
* <p>Information about the updated user pool replica.</p>
* @public
*/
UserPoolReplica?: UserPoolReplicaType | undefined;
}
/**
* @public
*/
export interface VerifySoftwareTokenRequest {
/**
* <p>A valid access token that Amazon Cognito issued to the currently signed-in user. Must include a scope claim for
* <code>aws.cognito.signin.user.admin</code>.</p>
* @public
*/
AccessToken?: string | undefined;
/**
* <p>The session ID from an <code>AssociateSoftwareToken</code> request.</p>
* @public
*/
Session?: string | undefined;
/**
* <p>A TOTP that the user generated in their configured authenticator app.</p>
* @public
*/
UserCode: string | undefined;
/**
* <p>A friendly name for the device that's running the TOTP authenticator.</p>
* @public
*/
FriendlyDeviceName?: string | undefined;
}
/**
* @public
*/
export interface VerifySoftwareTokenResponse {
/**
* <p>Amazon Cognito can accept or reject the code that you provide. This response parameter
* indicates the success of TOTP verification. Some reasons that this operation might
* return an error are clock skew on the user's device and excessive retries.</p>
* @public
*/
Status?: VerifySoftwareTokenResponseType | undefined;
/**
* <p>This session ID satisfies an <code>MFA_SETUP</code> challenge. Supply the session ID
* in your challenge response.</p>
* @public
*/
Session?: string | undefined;
}
/**
* <p>Represents the request to verify user attributes.</p>
* @public
*/
export interface VerifyUserAttributeRequest {
/**
* <p>A valid access token that Amazon Cognito issued to the currently signed-in user. Must include a scope claim for
* <code>aws.cognito.signin.user.admin</code>.</p>
* @public
*/
AccessToken: string | undefined;
/**
* <p>The name of the attribute that you want to verify.</p>
* @public
*/
AttributeName: string | undefined;
/**
* <p>The verification code that your user pool sent to the added or changed attribute, for
* example the user's email address.</p>
* @public
*/
Code: string | undefined;
}
/**
* <p>A container representing the response from the server from the request to verify user
* attributes.</p>
* @public
*/
export interface VerifyUserAttributeResponse {
}