Amazon Cognito introduces inbound federation Lambda triggers

Amazon Cognito Inbound Federation Lambda Triggers
Amazon Cognito now offers inbound federation Lambda triggers, allowing you to transform and customize federated user attributes during the authentication process. This feature enables you to modify responses from external SAML and OIDC providers before they are stored in your user pool, providing complete programmatic control over the federation flow without needing to change your identity provider configuration.
This new capability addresses limitations in federated authentication workflows, such as attribute size limits and the need for selective attribute storage from external identity providers. For instance, it allows you to handle large group attributes from external identity providers that exceed Cognito’s 2,048 character limit per attribute, preventing authentication flow blockages.
What to do
- Configure the trigger using the AWS Management Console, AWS CLI, AWS SDKs, CDK, or AWS CloudFormation by adding the new parameter to your User Pool LambdaConfig.
- Refer to the Amazon Cognito Developer Guide for implementation examples and best practices.
Source: AWS release notes
If you need further guidance on AWS, our experts are available at AWS@westloop.io. You may also reach us by submitting the Contact Us form.



