Amazon Cognito identity pools now support private connectivity with AWS PrivateLink

Amazon Cognito Identity Pools with AWS PrivateLink
Amazon Cognito identity pools now support AWS PrivateLink, enabling secure exchange of federated identities for AWS credentials through private connectivity between your VPC and Cognito. This eliminates public internet routing for authentication traffic, enhancing security for your workloads.
Identity pools map authenticated and guest identities to IAM roles, providing temporary AWS credentials via a secure and private connection.
Regions
Available in all AWS Regions except AWS China (Beijing) and AWS GovCloud (US).
Limits/Quotas
- VPC Endpoints: Additional charges apply for creating VPC endpoints on AWS PrivateLink.
What to do
- Create a VPC interface endpoint for Amazon Cognito identity pools using the AWS Management Console, CLI, SDKs, CDK, or CloudFormation.
- Refer to the documentation on creating a VPC interface endpoint and Amazon Cognito’s developer guide.
Source: AWS release notes
If you need further guidance on AWS, our experts are available at AWS@westloop.io. You may also reach us by submitting the Contact Us form.



