Amazon Cognito adds direct machine-to-machine authorization
Amazon Cognito now supports the new GetClientToken API operation, enabling app clients to obtain access tokens for machine-to-machine (M2M) authorization directly. This eliminates the need to configure a user pool domain, simplifying service-to-service communication for applications, microservices, and automated workloads. The API allows authentication with a client ID and secret, integrating seamlessly with AWS SDKs, AWS WAF, and VPC interface endpoints. This feature is generally available in all AWS Regions where Amazon Cognito user pools are supported, while the existing domain-based OAuth 2.0 flow remains an option.
Features (1) ›
- Enable machine-to-machine authorization without a user pool domain
Amazon Cognito now offers the GetClientToken API operation, allowing app clients to obtain access tokens for service-to-service communication directly via AWS SDK, CLI, or API. This new capability enables authentication using a client ID and secret, removing the previous requirement to configure a user pool domain for M2M authorization. The feature integrates with AWS WAF and VPC interface endpoints, offering an alternative to the existing domain-based OAuth 2.0 client-credentials flow.
https://aws.amazon.com/about-aws/whats-new/2026/08/amazon-cognito-get-client-token/
Related releases
- AWS Details Strategic Partnership with Upwind in Security Hub Extended AWS Security Blog ·
- Automated Security Response on AWS Adds AI Toolkit and Enhanced Remediation AWS What's New ·
- Amazon Redshift adds support for Apache Iceberg v3 tables AWS What's New ·
- AWS Elastic Beanstalk automates Active Directory domain join for Windows Server AWS What's New ·
- Amazon Redshift Enhances IAM Identity Center Integration with Private VPC Routing AWS Big Data Blog ·
- Automating AWS IAM Identity Center Governance with Discovery and Reporting AWS Security Blog ·