3 ms·
Unfortunately, we aren't able to read users' passwords from Cognito user pools, so they do have to reset them in the recovery environment. We'd love to see an
by sterwill 6y ago
Unfortunately, we aren't able to read users' passwords from Cognito user pools, so they do have to reset them in the recovery environment. We'd love to see an AWS API for exporting user secrets from user pools. We'd add support for that really quick.
The experience is better for user pools that integrate with external identity providers, like SAML, since the IdP metadata can be fully replicated into the other region ahead of time.
- time0ut 6y agoThat has been a barrier to us switching to Cognito. It'd save us a ton of money. Been asking AWS to support cross region replication for years now.
- doug_neumann 6y agoHave they ever given you a response? Cognito has so much unrealized potential...
- time0ut 6y agoYa but under NDA so can't go into it.
- doug_neumann 6y agoGotcha. I sure hope that NDA'd response is "we're about to unleash 'Cognito2' that rights all the wrongs of the current Cognito."
- leetrout 6y agoAt this point I regret using it and while I have some limited experience with both Ping and Okta I think I'm ready to move us to Auth0. AWS makes a simple move between user pools inexplicably difficult. They don't even offer an export and import in the same file format as far as I know (bulk export is all JSON via the CLI and import is CSV, but maybe I missed something). This is ridiculous in my opinion given that once a pool is configured you cannot change attributes (say, turning on a middle name field).
- leetrout 6y agoThanks for the answer. We were just discussing Cognito being a pretty significant single point of failure in our current setup (any vendor would be, though). I wish they would offer replication as the other commenter mentioned.