<a id="cognito"></a>

# Cognito

<a id="backend-class"></a>

## Backend class

For Django, add this class path to `AUTHENTICATION_BACKENDS`. For other
integrations, use the same class path in the framework-specific backend
setting.

| Backend name   | Class path                                   |
|----------------|----------------------------------------------|
| `cognito`      | `social_core.backends.cognito.CognitoOAuth2` |

Cognito implemented OAuth2 protocol for their authentication mechanism. To
enable `python-social-auth` support follow this steps:

Accounts are associated by the immutable `sub` claim. Associations created
by older social-core releases used `username` and migrate on the next
successful authentication.

1. Go to [AWS Cognito Console](https://console.aws.amazon.com/cognito/home) and select `Manage User Pools`.
2. Choose an existing pool or create a new one following the [Cognito Pool
   Tutorial](https://docs.aws.amazon.com/cognito/latest/developerguide/tutorial-create-user-pool.html).
3. Create an app (make sure to generate a client secret) and configure a pool
   domain ([Cognito App Configuration](GettingStartedforWeb:https://docs.aws.amazon.com/cognito/latest/developerguide/cognito-user-pools-configuring-app-integration.html)):
   ```default
   SOCIAL_AUTH_COGNITO_KEY = '...'
   SOCIAL_AUTH_COGNITO_SECRET = '...'
   SOCIAL_AUTH_COGNITO_POOL_DOMAIN = '...'
   ```
4. Enable the backend:
   ```default
   SOCIAL_AUTH_AUTHENTICATION_BACKENDS = (
       ...
       'social_core.backends.cognito.CognitoOAuth2',
       ...
   )
   ```
