Amazon Cognito now supports importing users with password hashes

Amazon Cognito Password Hash Import
Amazon Cognito now supports importing users with password hashes in CSV user imports. Previously, users imported from a CSV file had to reset their passwords on first sign-in. Now, you can include password hashes in your CSV file so that imported users can sign in immediately with their existing credentials.
When creating a CSV import, you specify the password hashing algorithm used by your source system. Amazon Cognito imports these users and verifies their password against the imported hash on first sign-in. Supported algorithms include bcrypt, scrypt, Argon2id, and PBKDF2 with SHA-256. All imported hashes receive an additional layer of cryptographic protection before storage.
What to do
- Create a user import using the AWS Management Console, AWS CLI, or AWS SDKs.
- Specify the password hashing algorithm used by your source system.
- Verify imported users can sign in with their existing credentials.
Password hash import is available in all AWS Regions where Amazon Cognito is available. See the developer guide for instructions.
Source: AWS release notes
If you need further guidance on AWS, our experts are available at AWS@westloop.io. You may also reach us by submitting the Contact Us form.



