Amazon Cognito introduces inbound federation Lambda triggers

Published
January 29, 2026
https://aws.amazon.com/about-aws/whats-new/2026/01/amazon-cognito-inbound-federation-lambda-trigger/

Amazon Cognito Inbound Federation Lambda Triggers

Amazon Cognito now offers inbound federation Lambda triggers, allowing you to transform and customize federated user attributes during the authentication process. This feature enables you to modify responses from external SAML and OIDC providers before they are stored in your user pool, providing complete programmatic control over the federation flow without needing to change your identity provider configuration.

This new capability addresses limitations in federated authentication workflows, such as attribute size limits and the need for selective attribute storage from external identity providers. For instance, it allows you to handle large group attributes from external identity providers that exceed Cognito’s 2,048 character limit per attribute, preventing authentication flow blockages.

What to do

  • Configure the trigger using the AWS Management Console, AWS CLI, AWS SDKs, CDK, or AWS CloudFormation by adding the new parameter to your User Pool LambdaConfig.
  • Refer to the Amazon Cognito Developer Guide for implementation examples and best practices.

Source: AWS release notes




If you need further guidance on AWS, our experts are available at AWS@westloop.io. You may also reach us by submitting the Contact Us form.

Follow our blog

Get the latest insights and advice on AWS services from our experts.

By clicking Sign Up you're confirming that you agree with our Terms and Conditions.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.