grill-me
Interview the user relentlessly about a plan or design until reaching shared understanding,…
Configuring Cognito Federation for Webiny projects — federated sign-in via external identity providers (Google, Facebook, Apple, Amazon, OIDC/Entra ID) while keeping Cognito as the user pool. Use this skill when the developer asks about Cognito federation, SSO with Cognito,
$ npx -y skills add webiny/webiny-js --skill cognito-federation --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/cognito-federationContext preview
The summary Claude sees to decide when to auto-load this skill.
Configuring Cognito Federation for Webiny projects — federated sign-in via external identity providers (Google, Facebook, Apple, Amazon, OIDC/Entra ID) while keeping Cognito as the user pool. Use this skill when the developer asks about Cognito federation, SSO with Cognito,
name: webiny-cognito-federation description: > Configuring Cognito Federation for Webiny projects — federated sign-in via external identity providers (Google, Facebook, Apple, Amazon, OIDC/Entra ID) while keeping Cognito as the user pool. Use this skill when the developer asks about Cognito federation, SSO with Cognito, adding Google/Microsoft/OIDC login to Cognito, federated identity providers, CognitoSignInConfig, CognitoIdpConfig, external users, signInWithRedirect, OAuth redirect URLs, hiding the password form, allowCredentialsLogin, or customizing the federated login screen.
Webiny supports federated sign-in through Cognito — users authenticate via external identity providers (Google, Entra ID, etc.) while Cognito remains the user pool. Configure it by adding a `federation` prop to `<Cognito />` in `webiny.config.tsx`. This handles both infrastructure (Cognito User Pool Domain, IdP resources, OAuth client) and the admin login screen (provider buttons, OAuth for Amplify). Federated users are auto-detected and synced into Webiny. For advanced use cases, provide `apiConfig` (custom identity mapping) and/or `adminConfig` (custom login screen behavior).
Cognito Federation has three layers:
1. **Infrastructure** — The `federation` prop on `<Cognito />`, under the hood, creates the Cognito User Pool Domain, Identity Provider resources, and configures OAuth on the User Pool Client.
2. **Admin Login Screen** — The federation config is passed as an `Admin.BuildParam` to the admin app. A `CognitoSignInConfig` abstraction provides the login screen with provider buttons, OAuth settings for Amplify, and credentials visibility. By default, this is auto-generated from the `federation` prop. For advanced customization (IP whitelists, async logic), provide an `adminConfig` extension.
3. **API Identity** — Federated tokens are auto-detected via the `identities` JWT claim and marked `external: true`. The `ExternalIdpUserSyncHandler` auto-creates/updates users on login. For custom role/team mapping, provide an `apiConfig` extension implementing `CognitoIdpConfig`.
1. User clicks a provider button on the login screen 2. `signInWithRedirect()` redirects to Cognito Hosted UI 3. Cognito redirects to the external IdP (Google, Entra ID, etc.) 4. After authentication, Cognito creates an `idToken` with an `identities` claim 5. The admin app picks up the session via `fetchAuthSession()` 6. The API detects `identities` in the token, sets `external: true` 7. `ExternalIdpUserSyncHandler` creates/updates the Webiny user with roles/teams
| Prop | Type | Description | | ------------- | --------------------------------- | ------------------------------------------------ | | `federation` | `object \| () => Promise<object>` | Federation config (see below) — sync or async | | `mfa` | `boolean` | Enable TOTP MFA for all users (default: `false`) | | `apiConfig` | `string` | Path to API identity mapping extension | | `adminConfig` | `string` | Path to Admin login customization extension |
| Field | Type | Required | Default | Description | | ----------------------- | ------------------- | -------- | -------------- | ------------------------------- | | `domain` | `string` | Yes | — | Cognito User Pool domain prefix | | `callbackUrls` | `string[]` | Yes | — | OAuth callback/redirect URLs | | `logoutUrls` | `string[]` | No | `callbackUrls` | OAuth logout redirect URLs | | `responseType` | `"code" \| "token"` | No | `"code"` | OAuth response type | | `allowCredentialsLogin` | `boolean` | No | `true` | Show email/password form | | `identityProviders` | `array` | Yes | — | List of federated IdPs |
| Field | Type | Required | Description | | ------------------ | --------------------------------------------------------- | -------- | ------------------------------------------------------------- | | `type` | `"google" \| "facebook" \| "amazon" \| "apple" \| "oidc"` | Yes | Provider type | | `name` | `string` | No | Custom provider name (required for OIDC) | | `label` | `string` | Yes | Button text on the login screen | | `providerDetails` | `object` | Yes | AWS Cognito provider details (client_id, client_secret, etc.) | | `attributeMapping` | `object` | No | Custom attribute mapping (overrides defaults) |
| Method | Signature | Description | | ------------- | ----------------------- | ---------------------------------------------- | | `getConfig()` | `() => Promise<Config>` | Returns federation config for the login screen |
| Field | Type | Required | Description | | ----------------------- | ------------------------------
Open-source content platform. Self-hosted on AWS serverless. Built as a TypeScript framework you extend with code, not a closed product you configure through a UI. Runs on Lambda, DynamoDB, S3, and CloudFront inside your own AWS account. Scales automatically.
Repo: webiny/webiny-js
Interview the user relentlessly about a plan or design until reaching shared understanding,…
Turn a PRD into a multi-phase implementation plan using tracer-bullet vertical slices, saved…
Webiny-only. Run all checks required before packages are ready for publish: deps, build,…
Use when running tests. Shows how to run tests for a single package, including OpenSearch…
Generate, refresh, and maintain Webiny MCP server skills from source documentation and…
Create a PRD through user interview, codebase exploration, and module design, then submit as…