Skip to content
Gauge

ax-check.com

Cognito

cognitohq.com

ax-check.com

Checked 7 October 2026

C

55/100

Agents need your login

Quickstart works well, but actual pricing page is missing

The API quickstart is concrete and self-contained, but the pricing link points to Plaid's page, not Cognito's own prices, units or limits.

4 fixes to start with

Concrete changes, backed by what we found.

Onboarding

Give agents a clear login handoff and a way to resume setup.

Agents cannot progress through onboarding without human help. Provide an agent-accessible path through authentication and setup.

Docs

Return Markdown when clients request text/markdown.

Homepage returned text/html for a text/markdown request; no Markdown representation offered.

Docs

Add links to your product documentation and quickstart in /llms.txt.

https://cognitohq.com/llms.txt returns HTTP 404, so no documentation index exists.

Docs

Publish a text or Markdown version of the quickstart.

No site-published Markdown guide; /llms.txt returns 404 and homepage serves HTML only.

Linked from cognitohq.com/docs/identity/id-verification-api-quickstart

Recorded coding sessions

Same task, 3 models, no cognitohq.com account. Recorded 7 October 2026 on Pi.

3 recorded · 2m 56s

2m 56s · recorded

Session findings

Select a finding to see it in context.

piv0.84.2
modelQwen 3.8 Maxcwd/sandbox/repo
Help me build a simple example using Cognito. Tell me how pricing works, and briefly tell me whether this product will be easy for you to manage. Let me know if you get blocked. If this product has no developer workflow you can act on, say so plainly and stop. Stay light: use the hosted product through its SDK or API. Do not start local service stacks or wait for long-running commands; if the quickstart requires either, say so plainly and stop.
Thinking…

The user is asking about AWS Cognito — building a simple example, pricing, and whether I can manage it. Let me check the environment: is there an AWS CLI, credentials, etc.?

First, let me take a look at the repository.

pwd; ls -la; echo "---"; git log --oneline -5 2>/dev/null | head
/sandbox/repo
/sandbox/repo
total 16
drwxr-xr-x 3 root root 4096 Sep 18 08:00 .
drwxr-xr-x 7 root root 4096 Oct  7 17:54 ..
drwxr-xr-x 8 root root 4096 Sep 24 20:05 .git
-rw-r--r-- 1 root root  408 Sep 18 08:00 .gitignore
---
9ebf5fb Initial workspace
which aws; aws --version 2>&1; echo "---"; env | grep -i -E 'aws|region' | sed 's/=.*SECRET.*/=<redacted>/'; echo "---"; ls ~/.aws 2>&1
Failed/bin/bash: line 1: aws: command not found
/bin/bash: line 1: aws: command not found
---
AWS_CA_BUNDLE=/etc/ssl/certs/ca-certificates.crt
---
ls: cannot access '/sandbox/.aws': No such file or directory


Command exited with code 2
Thinking…

No AWS CLI, no credentials. The repository is essentially empty. In other words, I can't actually provision Cognito resources or call the API. Should I check whether boto3 or other SDKs are available? And network access?

Let me quickly check.

python3 -c "import boto3; print(boto3.__version__)" 2>&1 | tail -2; node -e "try{require('aws-sdk');console.log('aws-sdk ok')}catch(e){console.log('no aws-sdk')}" 2>&1 | tail -1; ls /usr/local/lib/node_modules 2>/dev/null
File "<string>", line 1, in <module>
  File "<string>", line 1, in <module>
ModuleNotFoundError: No module named 'boto3'
no aws-sdk
@anthropic-ai
@earendil-works
@openai
corepack
npm
timeout 12 curl -sS -o /dev/null -w "%{http_code}\n" https://cognito-idp.us-east-1.amazonaws.com/ 2>&1 | tail -2; echo "--- npm reachable:"; timeout 12 curl -sS -o /dev/null -w "%{http_code}\n" https://registry.npmjs.org/ 2>&1 | tail -2
400
400
--- npm reachable:
200
Thinking…

Network is available. No credentials, no AWS CLI, no SDK. Therefore I cannot actually create a Cognito User Pool — I'd get blocked on credentials.

Following the user's instructions: tell them if blocked. Don't kick off local service stacks or long-running commands.

Best action: write code for a simple sample (Cognito SDK usage — e.g., a minimal Node.js app using aws-amplify, or a plain sign-up/sign-in flow via the boto3 / AWS SDK), make it runnable by the user, but explicitly state that I'm blocked from actually creating resources due to the lack of AWS credentials / CLI. That's honest and useful.

Keep it lightweight. Write a small Node example using @aws-sdk/client-cognito-identity-provider (admin-side), and also mention how to use hosted UI on the client side. Should I actually install the package? Installing npm packages is fine and quick. But without credentials I can't do anything. Still, writing a sample is actionable.

Let me narrow the focus: a single small sample directory containing:

  • README.md: quickstart steps (create User Pool via CLI or console), pricing, how to run
  • signup-signin.mjs using @aws-sdk/client-cognito-identity-provider

Let me quickly install the SDK and verify that the code loads (without network calls). That's a legitimate lightweight verification.

First, let me check the .gitignore.

cat .gitignore; node --version
# Keep generated and vendored files out of source diffs.
# Keep generated and vendored files out of source diffs.

# Logs / OS cruft
*.log
.DS_Store

# JavaScript / TypeScript
node_modules/
.next/
dist/
build/
coverage/

# Python
.venv/
venv/
__pycache__/
*.py[cod]
.pytest_cache/
*.egg-info/

# Rust
target/

# Go / PHP / Ruby vendored deps
vendor/
.bundle/

# Java / Kotlin / Scala
.gradle/

# .NET
bin/
obj/

# Elixir
_build/
deps/

# Dart / Flutter
.dart_tool/
v22.23.2
Thinking…

Write the sample. Use @aws-sdk/client-cognito-identity-provider. Install it to verify the imports work.

Code plan:

  • cognito-example/package.json
  • cognito-example/create-pool.mjs — create user pool + client (admin API), output the configuration
  • cognito-example/signup-signin.mjs — sign up a user, confirm via code (or use AdminCreateUser), sign in, obtain token, call whoami (GetUser)
  • cognito-example/.env.example
  • README.md

Keep it small. Alright, let's write it.

Actually, the simplest end-to-end that avoids the email-verification round trip is: create a user pool with email delivery via Cognito's built-in features, sign up → confirmation code required. For a script-only demo, use AdminCreateUser + AdminSetUserPassword + AdminInitiateAuth (USER_PASSWORD_AUTH) → token, then GetUser. That way it's fully scriptable without an inbox. I'll go with that.

Writing the files.

File edits

1 file

Completed
Writtencognito-example/package.jsonView changes

/sandbox/repo/cognito-example/package.json

Written content · previous contents were not recorded

{
"name": "cognito-example",
"version": "1.0.0",
"private": true,
"type": "module",
"description": "Minimal AWS Cognito (hosted product) walkthrough via the AWS SDK",
"scripts": {
"create-pool": "node create-pool.mjs",
"demo": "node signup-signin.mjs",
"cleanup": "node cleanup.mjs"
},
"dependencies": {
"@aws-sdk/client-cognito-identity-provider": "^3.0.0"
}
}

File edits

1 file

Completed
Writtencognito-example/config.mjsView changes

/sandbox/repo/cognito-example/config.mjs

Written content · previous contents were not recorded

import {
CognitoIdentityProviderClient,
} from "@aws-sdk/client-cognito-identity-provider";
// Region: env wins, else a sane default.
export const REGION = process.env.AWS_REGION || "us-east-1";
// Fill these in after `npm run create-pool` (or point them at an existing pool).
export const USER_POOL_ID = process.env.COGNITO_USER_POOL_ID || "";
export const CLIENT_ID = process.env.COGNITO_CLIENT_ID || "";
export const DEMO_USERNAME = process.env.DEMO_USERNAME || "demo-user";
export const DEMO_PASSWORD = process.env.DEMO_PASSWORD || "Demo!Passw0rd";
export const DEMO_EMAIL = process.env.DEMO_EMAIL || "demo@example.com";
export const client = new CognitoIdentityProviderClient({ region: REGION });
export function requirePool() {
if (!USER_POOL_ID || !CLIENT_ID) {
throw new Error(
"Missing COGNITO_USER_POOL_ID / COGNITO_CLIENT_ID. Run `npm run create-pool` first, then export the printed values.",
);
}
}
Thinking…

Now create-pool.mjs, signup-signin.mjs, cleanup.mjs, README.md.

Note: The new Cognito pricing is based on MAU and "advanced security." Also, features like user pools and SAML/OIDC federation are included. Let me try to recall the pricing accurately:

AWS Cognito pricing (as of the latest):

  • Cognito User Pools: Free for up to 50,000 MAU (Monthly Active Users) per month, then tiered: 50,001–100,000 at $0.0055 per MAU, 100,001–500,000 at $0.00425, 500,001–1,000,000 at $0.003825, and above 1,000,000 at $0.0025. (Actually, I think it's above 500k at $0.003825... let me recall: after the free 50k MAU: $0.0055/MAU for 50k–100k, $0.00425/MAU for 100k–500k, $0.003825/MAU for 500k–1M, $0.0025/MAU for above 1M.)
  • Advanced security features (managed): Included in many regions; was previously $0.05/MAU; now "essential" and "plus" tiers: Cognito advanced security - essential at $0.025 per MAU? Hmm. AWS changed this in 2024: advanced security features are now tiers "Advanced security – essential" ($0.05 per MAU? no...).

Let me be careful. I recall that in December 2024, AWS restructured: the Cognito user pools advanced security tiers are "essential" at $0.025/MAU and "plus" at $0.05/MAU? Actually, I think the announcement was "Amazon Cognito advanced security features are available in two tiers: essential ($0.025/MAU) and plus ($0.05/MAU)." Hmm, that doesn't quite feel right either. Let me avoid making things up: I'll state the base tier confidently, and treat the advanced security as an optional additional per-MAU charge (a few cents), and recommend checking the pricing page. Also mention: identity pools (federated identities) are free; MFA via SMS is billed separately through SNS charges; no charge for idle pools; charges only accrue when a user authenticates within a calendar month.

I should verify whether I can fetch the pricing page — network is available. It might be good to fetch https://aws.amazon.com/cognito/pricing/ and grep for numbers. That would be good due diligence. Let me try.

cd /tmp && timeout 25 curl -sSL -A "Mozilla/5.0" https://aws.amazon.com/cognito/pricing/ -o cog.html -w "%{http_code}\n"; python3 - <<'EOF'
import re,html
try:
    t=open('/tmp/cog.html',encoding='utf-8',errors='ignore').read()
except Exception as e:
    print('no file',e); raise SystemExit
t=re.sub(r'<script.*?</script>','',t,flags=re.S)
t=re.sub(r'<style.*?</style>','',t,flags=re.S)
t=re.sub(r'<[^>]+>',' ',t)
t=html.unescape(t)
t=re.sub(r'[ \t]+',' ',t)
lines=[l.strip() for l in t.split('\n') if l.strip()]
txt='\n'.join(lines)
i=txt.find('Monthly Active Users')
print(txt[max(0,i-200):i+3000] if i>0 else txt[:2000])
EOF
200
200
Amazon Cognito - Pricing
Skip to main content
Filter: All
English
Contact us
AWS Marketplace
Support
My account
re:Invent
Discover AWS
Products
Solutions
Pricing
Resources
Search
Filter: All
Sign in to console
Create account
Explore topics
re:Invent 2026
The session catalog is live. Explore what's waiting for you
Build & Deploy AI Agents
88% of agent pilots stall. Learn what the rest do differently
Independent Software Vendors
AI for software & tech: build, scale, and monetize
Data for agentic AI
The 7 essential data capabilities to scale agentic AI
Agent Toolkit
Give AI coding agents up-to-date docs and AWS resource access
Amazon Quick
Answers grounded in your actual business data
News & announcements
AWS blog
About AWS
AWS is the world's most comprehensive cloud, enabling organizations to accelerate innovation, reduce costs, and scale more efficiently
Why AWS
Getting Started
Security
Compliance
Trust Center
Sustainability
Global Infrastructure
Featured Products
Analytics
Application Integration
Artificial Intelligence
Business Applications
Compute
Customer Experience
Databases
Developer Tools
End User Computing
Game Tech
Management Tools
Media Services
Migration & Modernization
Multicloud & Hybrid
Networking & Content Delivery
Operations
Security & Identity
Storage
Supply Chain
Browse all products
Featured Products
Get started with one of these featured services or browse all Browse all products
Amazon Quick
AI-powered assistant for work with research, business insights, automation, and no-code app building
Transform
Eliminate tech debt with agentic AI to modernize legacy systems and code
Aurora
Serverless relational database service for PostgreSQL, MySQL, and DSQL
Amazon Bedrock
The end-to-end platform for building generative AI applications and agents
Amazon Connect Customer
AI-native solution for delivering exceptional experiences across customer interactions
EC2
Secure and resizable compute capacity for virtually any workload
Nova
Foundation models delivering 
Thinking…

The content of the pricing page is mostly navigation. Let me try grepping for the price value within the text.

cd /tmp && python3 - <<'EOF'
import re,html
t=open('/tmp/cog.html',encoding='utf-8',errors='ignore').read()
t=re.sub(r'<script.*?</script>','',t,flags=re.S)
t=re.sub(r'<style.*?</style>','',t,flags=re.S)
t=re.sub(r'<[^>]+>','|',t)
t=html.unescape(t)
t=re.sub(r'\|+','|',t)
t=re.sub(r'[ \t]+',' ',t)
for kw in ['MAU','$0.00','Monthly Active','Advanced security','free','Free']:
    for m in re.finditer(re.escape(kw),t):
        s=t[max(0,m.start()-160):m.start()+260].replace('\n',' ')
        print('###',kw,'::',s.strip()[:400]);print()
        break
EOF
### MAU :: entials and pay the same price as Cognito user pools until November 30, 2025. To be eligible, customers' accounts must have had at least 1 monthly ac
### MAU :: entials and pay the same price as Cognito user pools until November 30, 2025. To be eligible, customers' accounts must have had at least 1 monthly active user (MAU) in the last 12 months on or before 10:00am Pacific Time, November 22, 2024. These customers are also eligible to create new user pools with Essentials tier at the same price as Cognito users pools in those accounts until November 30, 2

### $0.00 :: enable these advanced security features for a user pool with 100,000 monthly active users, your monthly bill would be $495 for the base price for active users ($0.0055 per MAU past the 10,000 free tier) plus $4,250 for the advanced security features ($0.05 per MAU for the first 50,000 plus $0.035 per MAU for the next 50,000) for a total of $4,745.|  |  |  |SMS messages for Multi-Factor Authenticat

### Advanced security :: for monthly active users as shown in the table below. This includes audit mode. ASF pricing is the same as the pricing was listed before November 22, 2024.|  |Advanced security features include |compromised credentials detection|, |adaptive authentication|, |advanced security metrics|, and |access token customization|. If you enable advanced security features for Amazon Cognito, additional prices 

### free :: |  |  |  |  |AWS Pricing Calculator|  |Estimate the cost for your architecture solution|  |  |  |  |  |  |  |  |  |  |  |  |  |  |  |  |  |AWS Free Tier|  |Get free, hands-on experience with AWS products and services|  |  |  |  |  |  |  |  |  |  |  |  |  |  |  |  |  |AWS Offers|  |Explore different offer programs to gain hands-on experience|  |  |  |  |  |  |  |  |  |  |  |  |  |  |  |  |  |AWS Sa

### Free :: |  |  |  |  |  |  |  |  |  |AWS Pricing Calculator|  |Estimate the cost for your architecture solution|  |  |  |  |  |  |  |  |  |  |  |  |  |  |  |  |  |AWS Free Tier|  |Get free, hands-on experience with AWS products and services|  |  |  |  |  |  |  |  |  |  |  |  |  |  |  |  |  |AWS Offers|  |Explore different offer programs to gain hands-on experience|  |  |  |  |  |  |  |  |  |  |  |  |  |  |

Thinking…

The pricing page mentions "the $0.0055 per MAU rate beyond the 10,000 free tier" — interesting: that example says 10,000 free. Note: this reflects the new (November 2024) pricing structure: Cognito user pools now have tiers "Essentials" and "Plus"? Let's extract the actual pricing table. I'll search for the "Essentials" and "Plus" tiers as well as the tiered rates.

cd /tmp && python3 - <<'EOF'
import re,html
t=open('/tmp/cog.html',encoding='utf-8',errors='ignore').read()
t=re.sub(r'<script.*?</script>','',t,flags=re.S)
t=re.sub(r'<style.*?</style>','',t,flags=re.S)
t=re.sub(r'<[^>]+>','|',t)
t=html.unescape(t); t=re.sub(r'\|+','|',t); t=re.sub(r'[ \t]+',' ',t)
i=t.find('Cognito user pools pricing')
if i<0: i=t.find('user pools')
print(t[i-500:i+4200].replace('\n',' '))
EOF
| | | | | |Pricing overview| | | | | | | | | | | |With Amazon Cognito, you pay only for what you use. There are no minimum fees and no upfront
 |  |  |  |  |  |Pricing overview|  |  |  |  |  |  |  |  |  |  |  |With Amazon Cognito, you pay only for what you use. There are no minimum fees and no upfront commitments. Amazon Cognito charges for identity management and data synchronization, and the pricing for these features are described below.|  |  |  |  |        |  |  |  |  |  |  |  |  |  |  |  |  |  |  |  |  |  |    |  |  |  |  |  |  |  |Pricing tiers|  |Amazon Cognito offers you three pricing tiers to choose from when configuring your user pools, each priced based on your usage:|  |  |  |  |  |  |  |  |Lite|  |  |Lite provides basic user registration, authentication, and management capabilities, including social identity and SAML/OIDC provider integration, and password-based authentication. Lite is targeted for value-oriented use-cases. It includes all Cognito user pool capabilities (without advanced security features) available before November 22, 2024.|  |  |  |  |Essentials|  |  |Essentials offers comprehensive and flexible user authentication and access control features, allowing customers to implement secure, scalable, and customized sign-up and sign-in experiences for their application within minutes. It includes all capabilities in Lite along with supporting Managed Login and passwordless login options using passkeys, email, or SMS. Essentials also supports customizing access tokens and disallowing password reuse.|  |  |  |  |Plus|  |  |Plus is geared toward customers with elevated security needs for their applications by offering threat protection capabilities against suspicious log-ins. It includes all Essentials tier features and additionally supports risk-based adaptive authentication, compromised credentials detection, and exporting user authentication event logs to analyze threat signals.|  |  |  |  |  |  |  |  |  |  |  |  |  |  |  |  |  |  |Note:|  |  |Essentials will be the default tier for new users pools created by customers. Customers have the flexibility to switch their user pools between the Lite, Essentials, or Plus tiers anytime based on their application needs. |  |Customers are eligible to upgrade their user pools without advanced security features (ASF) in their existing accounts to Essentials and pay the same price as Cognito user pools until November 30, 2025. To be eligible, customers' accounts must have had at least 1 monthly active user (MAU) in the last 12 months on or before 10:00am Pacific Time, November 22, 2024. These customers are also eligible to create new user pools with Essentials tier at the same price as Cognito users pools in those accounts until November 30, 2025.|  |Customers with ASF enabled in their user pools will continue paying based on the existing Cognito ASF price. Customers using ASF in Amazon Cognito should consider the Plus tier, which includes all ASF capabilities, additional capabilities such as passwordless log-in, and up to 60% savings compared to using ASF. |  |  |  |  |  |  |  |  |  |Free Tier|  |  |Amazon Cognito Essentials and Lite have a free tier. The free tier does not automatically expire at the end of your 12-month AWS Free Tier term, and it is available to both existing and new AWS customers indefinitely. Please note - the free tier pricing isn’t available in the AWS GovCloud (US) Regions.|  |1. For users who sign in directly via Amazon Cognito or through a social identity provider, Amazon Cognito user pools has a free tier of 10,000 monthly active user (MAU) per month per account or per AWS organization. This free tier is applicable for customers that configure their user pools to either the Lite or Essentials tier. There is no free tier for the Plus tier.|  |2. For users federated through SAML 2.0 or an OpenID Connect (OIDC) identity provider, Amazon Cognito user pools has a free tier of 50 MAUs per month per account or per AWS organization regardless of your user pool pricing tier configuration.|  |3. There is no free tier for token requests when Cognito is used for the machine-to-machine use case.|  |4. Use of Amazon Cognito identity pools for authenticating users and generating unique identifiers is provided at no charge.|  |To learn more about AWS Free Tier, refer to the FAQs (|https://aws.amazon.com/free/free-tier-faqs/|)|  |  |  |  |Pricing table for Amazon Cognito tiers|  |  |  |  |  |  Essentials  |  |  |  |  |  Plus  |  |  |  |  |  Lite  |  |  |  |  |  |  Essentials  |  |  |  |  |You pay for Amazon Cognito Essentials based on monthly active users (MAUs) in your user pool configured with pricing tier of Essentials. A user is counted as Essentials MAU if the user is active at least once in a month when the user pool pricing tier is configured as Essentials and was never activ
Thinking…

Get the actual per-MAU rates for each tier. Continue extraction.

cd /tmp && python3 - <<'EOF'
import re,html
t=open('/tmp/cog.html',encoding='utf-8',errors='ignore').read()
t=re.sub(r'<script.*?</script>','',t,flags=re.S); t=re.sub(r'<style.*?</style>','',t,flags=re.S)
t=re.sub(r'<[^>]+>','|',t); t=html.unescape(t); t=re.sub(r'\|+','|',t); t=re.sub(r'[ \t]+',' ',t)
i=t.find('You pay for Amazon Cognito Essentials based on')
print(t[i:i+5000].replace('\n',' '))
EOF
You pay for Amazon Cognito Essentials based on monthly active users (MAUs) in your user pool configured with pricing tier of Essentials. A user is counted as Es
You pay for Amazon Cognito Essentials based on monthly active users (MAUs) in your user pool configured with pricing tier of Essentials. A user is counted as Essentials MAU if the user is active at least once in a month when the user pool pricing tier is configured as Essentials and was never active when the user pool was configured as Plus.|  |Essentials will be the default tier for new users pools created by customers. Customers have the flexibility to switch their user pools between the Lite, Essentials, or Plus tiers anytime based on their application needs.|  |Note|: Customers are eligible to upgrade their user pools without advanced security features (ASF) in their existing accounts to Essentials and pay the same price as Cognito user pools until November 30, 2025. To be eligible, customers' accounts must have had at least 1 MAU in the last 12 months on or before 10:00am Pacific Time, November 22, 2024. These customers are also eligible to create new user pools with Essentials tier at the same price as Cognito users pools in those accounts until November 30, 2025.|  |There is separate pricing for users who sign in directly with their credentials from a user pool (includes social identity providers) and for users who sign in through an enterprise directory with SAML federation. For users who sign in through SAML or OIDC federation, the price for MAUs above the 50 MAU free tier is $0.015. This is the same pricing as previously listed before November 22, 2024. For users who sign in directly with their credentials from a user pool (includes social identity providers), their price per MAU is listed in the table below.|  |  |{regionSelector}| | | |MAUs|Price per MAU| | | |First 10,000 (Free-tier)|{priceOf!cognito/cognito!0t0XCtu1K5oc7qNe4hGefP86r5iFH8cYH-K7icfb7G4}| |Greater than 10,000|{priceOf!cognito/cognito!8NjKZgrBYoou8EPp1jVd256Efk6-Vbn0viBomRlyDY0}| | | " data-pricing-endpoint="https://b0.p.awsstatic.com/pricing/2.0/meteredUnitMaps" data-partition="aws" data-locale="en-US" data-token-component-type="native-react">|  |  |SMS messages for Multi-Factor Authentication (MFA)|  |Separate pricing applies for sending SMS messages for Multi-Factor Authentication (MFA), user registration, password recovery, and phone number verification. Amazon Cognito uses Amazon Simple Notification Service (SNS) to send SMS messages, and you can reference |Amazon SNS pricing|.|  |Email messages for user verification|  |Separate pricing applies for sending email messages for user registration, password recovery, and email address verification. Amazon Cognito uses Amazon Simple Email Service (SES) to send email messages, and you can reference |Amazon SES pricing|.|  |  |  |  |  |  |Example 1: Your user pool is configured with Amazon Cognito Essentials as pricing tier|  |  |  |  |If your Cognito user pool has 950,000 MAUs and all MAUs sign-in directly or via social identity providers, then your monthly bill will be computed as follows:|  |Total number of MAUs billed above the 10,000 MAU free tier = 950,000 – 10,000 = 940,000|  |Price / MAU charged above the free tier = $0.015|  |Total monthly bill = $0.015 x 940,000 = $14,100|  |Cognito Essentials MAU cost (monthly): $14,100|  |  |  |  |  |Example 2: Your user pool is configured with Amazon Cognito Essentials as pricing tier and you have active users signing in via SAML/OIDC federation.|  |  |  |  |If your Cognito user pool has 950,000 MAUs and out of these MAUs, 945,000 MAUs sign-in directly or via social identity providers, and 5,000 MAUs sign-in via SAML/OIDC federation, then your monthly bill will be computed as follows: |Bill for users signing-in directly or via social identity providers| |  Total number of MAUs billed above the 10,000 MAU free tier = 945,000 – 10,000 = 935,000 |  Price / MAU charged above the free tier for Essentials tier = $0.015 |  Monthly bill = $0.015 x 935,000 = $14,025 |Bill for users signing-in via SAML/OIDC providers| |  Total number of MAUs billed above the 50 MAU free tier = 5,000 - 50 = 4,950 |  Price / MAU charged above the free tier for login via SAML/OIDC providers = $0.015 |  Monthly bill = $0.015 x 4,950 = $74.25 |  Total Cognito monthly bill = $14,025 + $74.25 = $14,099.25 |  |  |  |  |  |  |  |  |  |  |  |  |  Plus  |  |  |  |  |You pay for Amazon Cognito Plus based on monthly active users (MAUs) in your user pool configured with pricing tier of Plus. A user is counted as Plus MAU if the user is active at least once in a month when the user pool pricing tier is configured as Plus.|  |Note|: Customers with accounts using Amazon Cognito user pools configured with Advanced Security Features (ASF) can save up to 60% on their monthly bill by configuring their user pool with Plus pricing tier.|  |There is separate pricing for users who sign in directly with their credentials from a user pool (includes social identity providers) and for users who sign in through an enterprise directory with SAML federation. For users who sign in through SAML or
Thinking…

Alright. Next, I'll grab the Plus and Lite rates. The examples state Essentials at $0.015/MAU. Let me quickly grab the Plus and Lite numbers.

cd /tmp && python3 - <<'EOF'
import re,html
t=open('/tmp/cog.html',encoding='utf-8',errors='ignore').read()
t=re.sub(r'<script.*?</script>','',t,flags=re.S); t=re.sub(r'<style.*?</style>','',t,flags=re.S)
t=re.sub(r'<[^>]+>','|',t); t=html.unescape(t); t=re.sub(r'\|+','|',t); t=re.sub(r'[ \t]+',' ',t)
for m in re.finditer(r'Price / MAU charged above the free tier[^|]{0,120}',t):
    print('*',m.group(0)[:160])
print('---')
i=t.find('Example 1: Your user pool is configured with Amazon Cognito Plus')
print(t[i:i+900].replace('\n',' ') if i>0 else 'plus example not found')
print('---LITE---')
j=t.find('Example 1: Your user pool is configured with Amazon Cognito Lite')
print(t[j:j+900].replace('\n',' ') if j>0 else 'lite example not found')
EOF
* Price / MAU charged above the free tier = $0.015
* Price / MAU charged above the free tier = $0.015
* Price / MAU charged above the free tier for Essentials tier = $0.015 
* Price / MAU charged above the free tier for login via SAML/OIDC providers = $0.015 
* Price / MAU charged above the free tier = $0.020
---
plus example not found
---LITE---
Example 1: Your user pool is configured with Amazon Cognito Lite as pricing tier|  |  |  |  |If your Cognito user pool has 950,000 MAUs and all MAUs sign-in directly or via social identity providers, then your monthly bill will be computed as follows:|  |Total number of MAUs billed above the 10,000 MAU free tier = 950,000 – 10,000 = 940,000|  |Tiered price for: 940,000 MAUs|  |90,000 MAUs x $0.0055 = $495|  |850,000 MAUs x $0.0046 = $3,910|  |Total monthly bill = $495 + $3,910 = $4,405|  |Cognito Lite MAU cost (monthly): $4,405|  |  |  |  |  |Example 2: Your user pool is configured with Amazon Cognito Lite as pricing tier with ASF enabled|  |  |  |  |If your Cognito user pool has 950,000 MAUs and all MAUs sign-in directly or via social identity providers, then your monthly bill will be computed as follows:|  |Total number of MAUs billed above the 10,000 MAU free tier = 950,000 – 10,000 =
Thinking…

The Plus tier is $0.020 per MAU (above the free tier. Plus has no free tier, but—though the example says "the portion exceeding the free tier of 10,000 MAU," the free-tier description states that Plus has no free tier. In the example, the free tier is being deducted... whatever. I'll write "Plus is roughly $0.02 per MAU, and Plus has no free tier"—hmm, contradictory. The safer phrasing is: Lite/Essentials have a 10,000 MAU free tier. Plus has no free tier (per the free-tier description). Rates: Lite uses the legacy tiered pricing (10,001–50,000 at $0.0055/MAU, 50,001–100,000 at $0.0046?… actually the example says "90,000 × $0.0055," which suggests the first 100,000 after the free tier is $0.0055, and then 850,000 × $0.0046"). Hmm: 940,000 − 90,000 = 850,000. So the tiers are: first 90,000 after the free tier? That's weird—the legacy tiers were 50,001–100,000: $0.0055, 100,001–500,000: $0.00425… no wait, $0.0046 doesn't match. Legacy Lite pricing (post-Nov 2024): first 10,000 free, next 90,000 (10,001–100,000) at $0.0055, next 400,000 (100,001–500,000) at $0.0046, 500,001–1,000,000 at $0.00414, above 1 million at $0.0027? I'm not sure. For Lite I'll present a rough tiered structure, but keep it brief and point them to the pricing page. The user asked "tell me how the pricing works"—a concise summary is enough, no need for exhaustive numbers.

Summary for the response:

  • Pay-as-you-go, no upfront costs. Billing is per MAU (a user who authenticates at least once in a calendar month).
  • Three tiers: Lite (basic + social/SAML/OIDC, password auth), Essentials (default. Managed Login branding, passkeys/email/SMS passkeyless, access token customization), Plus (adds adaptive authentication, credential stuffing detection, event logs).
  • Lite and Essentials have a free tier: first 10,000 MAU per month per account/organization is free, indefinite (not just the first 12 months). SAML/OIDC federated users: 50 MAU free, then $0.015 per MAU. Essentials: $0.015 per MAU over the free tier. Plus: about $0.02 per MAU, no free tier. Lite uses the legacy volume-tiered pricing (starting around $0.0055/MAU).
  • Identity pools (federated identities) are free.
  • SMS MFA is billed via SNS, email verification is billed via SES. M2M token requests have no free tier.
  • An idle pool (no active users) is $0. So this sample costs nothing.

Next, I'll write the sample script and README. Then verify that npm install and the script run correctly (should fail with a clear credentials error). Actually, without credentials, the SDK will throw at call time—good, that demonstrates the blocked state.

Now I'll write the files.

File edits

1 file

Completed
Writtencognito-example/create-pool.mjsView changes

/sandbox/repo/cognito-example/create-pool.mjs

Written content · previous contents were not recorded

// Creates a minimal Cognito user pool + app client using the hosted Cognito API.
// Nothing runs locally: this is just HTTPS calls to AWS.
import {
CreateUserPoolCommand,
CreateUserPoolClientCommand,
} from "@aws-sdk/client-cognito-identity-provider";
import { client, REGION } from "./config.mjs";
const POOL_NAME = process.env.COGNITO_POOL_NAME || "pi-demo-pool";
const pool = await client.send(
new CreateUserPoolCommand({
PoolName: POOL_NAME,
// Cheapest tier; switch to "ESSENTIALS" (default) for Managed Login/passkeys.
UserPoolTier: "LITE",
AutoVerifiedAttributes: ["email"],
UsernameAttributes: ["email"],
Schema: [
{ Name: "email", AttributeDataType: "String", Required: true, Mutable: true },
],
Policies: {
PasswordPolicy: {
MinimumLength: 8,
RequireUppercase: true,
RequireLowercase: true,
RequireNumbers: true,
RequireSymbols: false,
},
},
}),
);
const appClient = await client.send(
new CreateUserPoolClientCommand({
UserPoolId: pool.UserPool.Id,
ClientName: "pi-demo-client",
// No client secret => usable directly from a browser/mobile app.
GenerateSecret: false,
ExplicitAuthFlows: [
"ALLOW_USER_PASSWORD_AUTH", // script-friendly; prefer SRP/refresh in production
"ALLOW_REFRESH_TOKEN_AUTH",
],
PreventUserExistenceErrors: "ENABLED",
}),
);
console.log(`Region: ${REGION}`);
console.log(`User pool ID: ${pool.UserPool.Id}`);
console.log(`Client ID: ${appClient.UserPoolClient.ClientId}`);
console.log("\nNext:");
console.log(` export COGNITO_USER_POOL_ID=${pool.UserPool.Id}`);
console.log(` export COGNITO_CLIENT_ID=${appClient.UserPoolClient.ClientId}`);
console.log(" npm run demo");

File edits

1 file

Completed
Writtencognito-example/signup-signin.mjsView changes

/sandbox/repo/cognito-example/signup-signin.mjs

Written content · previous contents were not recorded

// End-to-end Cognito demo against the hosted service:
// 1. admin-creates a user with a known password (skips the email/SMS code round trip)
// 2. signs in with username+password and receives OIDC tokens
// 3. uses the access token to call GetUser ("who am I?")
// 4. decodes the ID token so you can see what Cognito puts in it
import {
AdminCreateUserCommand,
AdminSetUserPasswordCommand,
InitiateAuthCommand,
GetUserCommand,
} from "@aws-sdk/client-cognito-identity-provider";
import {
client,
requirePool,
USER_POOL_ID,
CLIENT_ID,
DEMO_USERNAME,
DEMO_PASSWORD,
DEMO_EMAIL,
} from "./config.mjs";
requirePool();
// 1. Create the user directly as an admin, then set a permanent password.
try {
await client.send(
new AdminCreateUserCommand({
UserPoolId: USER_POOL_ID,
Username: DEMO_USERNAME,
UserAttributes: [{ Name: "email", Value: DEMO_EMAIL }],
// MessageAction SUPPRESS = don't email/SMS an invite code.
MessageAction: "SUPPRESS",
}),
);
console.log(`Created user "${DEMO_USERNAME}"`);
} catch (err) {
if (err.name !== "UsernameExistsException") throw err;
console.log(`User "${DEMO_USERNAME}" already exists, continuing`);
}
await client.send(
new AdminSetUserPasswordCommand({
UserPoolId: USER_POOL_ID,
Username: DEMO_USERNAME,
Password: DEMO_PASSWORD,
Permanent: true,
}),
);
// 2. Sign in and get tokens.
const auth = await client.send(
new InitiateAuthCommand({
AuthFlow: "USER_PASSWORD_AUTH",
ClientId: CLIENT_ID,
AuthParameters: { USERNAME: DEMO_USERNAME, PASSWORD: DEMO_PASSWORD },
}),
);
const { AccessToken, IdToken, RefreshToken, ExpiresIn } = auth.AuthenticationResult;
console.log(`\nSigned in. Access token expires in ${ExpiresIn}s`);
console.log(`Access token: ${AccessToken.slice(0, 32)}...`);
console.log(`Refresh token: ${RefreshToken.slice(0, 32)}...`);
// 3. Call an authenticated API with the access token.
const me = await client.send(
new GetUserCommand({ AccessToken }),
);
console.log(`\nGetUser -> username="${me.Username}"`);
for (const attr of me.UserAttributes) console.log(` ${attr.Name} = ${attr.Value}`);
// 4. Peek inside the ID token (JWT) without verifying it.
const payload = JSON.parse(
Buffer.from(IdToken.split(".")[1], "base64url").toString(),
);
console.log("\nID token claims:");
console.log(` sub: ${payload.sub}`);
console.log(` email: ${payload.email}`);
console.log(` iss: ${payload.iss}`);
console.log(` exp: ${new Date(payload.exp * 1000).toISOString()}`);

File edits

1 file

Completed
Writtencognito-example/cleanup.mjsView changes

/sandbox/repo/cognito-example/cleanup.mjs

Written content · previous contents were not recorded

// Deletes the demo user pool so you stop accruing (zero) charges and clutter.
import {
ListUserPoolsCommand,
DeleteUserPoolCommand,
} from "@aws-sdk/client-cognito-identity-provider";
import { client, USER_POOL_ID } from "./config.mjs";
const POOL_NAME = process.env.COGNITO_POOL_NAME || "pi-demo-pool";
let poolId = USER_POOL_ID;
if (!poolId) {
const pools = await client.send(
new ListUserPoolsCommand({ MaxResults: 60 }),
);
const match = (pools.UserPools || []).find((p) => p.Name === POOL_NAME);
if (!match) {
console.log(`No pool named "${POOL_NAME}" found; nothing to do.`);
process.exit(0);
}
poolId = match.Id;
}
await client.send(new DeleteUserPoolCommand({ UserPoolId: poolId }));
console.log(`Deleted user pool ${poolId}`);
Thinking…

Next up is README.md, and then I'll install the dependencies and do a smoke test to confirm that the script can load, and that it fails cleanly due to insufficient credentials (which will prove that the blocker is real).

File edits

1 file

Completed
Writtencognito-example/README.mdView changes

/sandbox/repo/cognito-example/README.md

Written content · previous contents were not recorded

# Cognito example (hosted AWS service, SDK only)
A minimal end-to-end walkthrough of **Amazon Cognito user pools** using the
official AWS SDK for JavaScript. Everything talks to the hosted Cognito API —
no local emulators, no containers, no LocalStack.
## Files
| File | What it does |
|---|---|
| `create-pool.mjs` | Creates a user pool (Lite tier) + a public app client, prints the IDs |
| `signup-signin.mjs` | Creates a demo user, signs in, calls `GetUser`, decodes the ID token |
| `cleanup.mjs` | Deletes the demo user pool |
| `config.mjs` | Shared client + env-var config |
## Prerequisites
- An AWS account and credentials with permission to manage Cognito
(`AmazonCognitoPowerUser` is enough for this demo).
- Credentials via any standard mechanism: `aws configure`, env vars
(`AWS_ACCESS_KEY_ID` / `AWS_SECRET_ACCESS_KEY` / `AWS_SESSION_TOKEN`),
SSO, or an IAM role.
## Run
```bash
cd cognito-example
npm install
# 1. Create the pool (prints the two IDs you need)
npm run create-pool
# 2. Export what it printed
export COGNITO_USER_POOL_ID=us-east-1_XXXXXXXXX
export COGNITO_CLIENT_ID=xxxxxxxxxxxxxxxxxxxxxxxxxx
# 3. Sign up / sign in / inspect tokens
npm run demo
# 4. Tear down
npm run cleanup
```
Optional env overrides: `AWS_REGION` (default `us-east-1`), `DEMO_USERNAME`,
`DEMO_PASSWORD`, `DEMO_EMAIL`, `COGNITO_POOL_NAME`.
## What the demo proves
- Cognito issues standard **OIDC tokens**: an access token (for calling APIs),
an ID token (JWT with `sub`, `email`, `iss`, `exp`), and a refresh token.
- A user pool can be fully managed by API — create pool, create client,
create user, authenticate — with zero infrastructure to operate.
## Real-app notes (beyond this demo)
- **Frontend apps**: don't use `USER_PASSWORD_AUTH` from a browser. Use the
hosted **Managed Login** page (OAuth2 redirect flow) or Amplify Auth, and
`ADMIN_USER_PASSWORD_AUTH`/SRP only server-side.
- The demo creates the user via admin APIs to avoid an email/SMS verification
round trip. In production, use public `SignUp` + `ConfirmSignUp` with the
code Cognito sends.
- Set `GenerateSecret: true` for confidential (server-side) clients.
## Pricing (Cognito user pools)
Pay-per-use, billed on **monthly active users (MAU)** — a user who
authenticates at least once in a calendar month. No charge for provisioned
capacity, idle pools, or stored users.
- **Free tier**: first **10,000 MAU/month** free per account/org for the Lite
and Essentials tiers, and it does **not** expire after 12 months.
- **Tiers** (per user pool): **Lite** (basic auth + social/SAML/OIDC, volume-
tiered from ~$0.0055/MAU), **Essentials** (default; Managed Login, passkeys/
passwordless, token customization; **$0.015/MAU** above free tier), **Plus**
(adaptive auth, compromised-credentials detection, event logs;
~**$0.020/MAU**, no free tier).
- **SAML/OIDC-federated** users: 50 MAU free, then $0.015/MAU.
- **Cognito identity pools** (federated identities / AWS credential vending):
free.
- Extras billed by the underlying service: SMS MFA via **SNS**, verification
emails via **SES**. Machine-to-machine token requests get no free tier.
This demo costs **$0** (one active user, well under the free tier).
See <https://aws.amazon.com/cognito/pricing/> for current regional rates.
Thinking…

Next, install the dependencies, do a smoke test, and confirm that the script can be loaded. Then run create-pool to demonstrate the credentials blocker (it should immediately fail with a clear credentials error—since it errors out immediately, it won't be a long-running execution). Set a short timeout.

cd cognito-example && timeout 180 npm install --no-audit --no-fund 2>&1 | tail -3
npm notice Changelog: https://github.com/npm/cli/releases/tag/v12.2.0
npm notice Changelog: https://github.com/npm/cli/releases/tag/v12.2.0
npm notice To update run: npm install -g npm@12.2.0
npm notice
Thinking…

The user resubmitted the same request. I was in the middle of the work: the file has already been written, npm install is complete (the output was truncated to the npm notice line, so I need to confirm that the install succeeded). After that, I'll do a smoke test of the script (I'm expecting a credentials error), and then provide a final answer that includes the pricing and admin evaluation.

cd cognito-example && ls node_modules/@aws-sdk 2>/dev/null | head -3; node -e "import('@aws-sdk/client-cognito-identity-provider').then(m=>console.log('SDK loads OK, exports:',Object.keys(m).length)).catch(e=>{console.error('FAIL',e.message);process.exit(1)})"
client-cognito-identity-provider
client-cognito-identity-provider
core
credential-provider-env
SDK loads OK, exports: 805
Thinking…

The SDK loads without issues. Next, smoke-test the two scripts: the demo should fail with a clear "Missing COGNITO_USER_POOL_ID" error (requirePool), and create-pool should fail with a credentials error — confirming the blocker. Running create-pool without credentials: the SDK will attempt the credential provider chain and quickly throw CredentialsProviderError. Not a long-running execution. Let's run both with a short timeout.

cd cognito-example && echo "=== demo (no pool IDs set) ==="; timeout 30 node signup-signin.mjs 2>&1 | head -5; echo; echo "=== create-pool (no AWS creds) ==="; timeout 30 node create-pool.mjs 2>&1 | grep -E 'Error|error|Credentials' | head -4
=== demo (no pool IDs set) ===
=== demo (no pool IDs set) ===
file:///sandbox/repo/cognito-example/config.mjs:20
    throw new Error(
          ^

Error: Missing COGNITO_USER_POOL_ID / COGNITO_CLIENT_ID. Run `npm run create-pool` first, then export the printed values.

=== create-pool (no AWS creds) ===
        throw new CredentialsProviderError("Could not load credentials from any providers", {
CredentialsProviderError: Could not load credentials from any providers
Thinking…

Both fail-fast paths work exactly as designed. Everything that can be verified without an AWS account has been verified. Time for the final answer:

  1. What I built (files, flow)
  2. Where I got blocked: no AWS credentials in this sandbox (no AWS CLI, no ~/.aws, no environment variables) — so I can't actually create a real user pool or do a real sign-in. The code will fail immediately and cleanly.
  3. How pricing works (verified from the live AWS pricing page)
  4. Ease-of-management assessment
  5. Confirmed: no local stack needed, no long-running commands needed — Cognito has an actual developer workflow via SDK/API, so I didn't abort for that reason; the only blocker is credentials.

Done. Everything is built and verified as far as this sandbox allows. Here's the summary:

What I built — cognito-example/

A minimal end-to-end Cognito user pools walkthrough using the official AWS SDK (@aws-sdk/client-cognito-identity-provider). Pure HTTPS calls to the hosted service — no local stack, no containers, nothing long-running.

FilePurpose
create-pool.mjsCreates a user pool (Lite tier) + public app client, prints the IDs
signup-signin.mjsCreates a demo user, signs in, calls GetUser with the access token, decodes the ID token JWT
cleanup.mjsDeletes the demo pool
config.mjs / README.mdShared config / full run instructions

Verified: SDK installs and loads (805 exports), and both scripts fail fast with clear messages in the expected pre-conditions (missing pool IDs, missing credentials).

Where I'm blocked

No AWS credentials in this sandbox — no AWS CLI, no ~/.aws, no AWS_* env vars. So I can write and smoke-test the workflow, but I can't create a real user pool or do a real sign-in. create-pool.mjs fails immediately with CredentialsProviderError: Could not load credentials from any providers. If you drop credentials in (env vars or aws configure), the three npm run commands complete the whole loop in seconds.

Pricing (checked against the live AWS pricing page)

Pay-per-use on monthly active users (MAU) — anyone who authenticates at least once in a calendar month. No charge for stored users, idle pools, or provisioned capacity.

  • Free tier: first 10,000 MAU/month free per account/org (Lite & Essentials tiers), and it never expires after 12 months.
  • Three pool tiers: Lite (~$0.0055+/MAU volume-tiered, basic + social/SAML/OIDC), Essentials (default; Managed Login, passkeys/passwordless; $0.015/MAU above free tier), Plus (adaptive auth, compromised-credential detection; ~$0.020/MAU, no free tier).
  • SAML/OIDC-federated users: 50 MAU free, then $0.015/MAU. Identity pools are free. SMS MFA bills via SNS, verification email via SES.
  • This demo costs $0 (1 active user, way under the free tier).

Will this be easy for me to manage?

Yes — it's close to ideal for agent management. Cognito has a complete control-plane API (everything in the demo, including pool deletion for cleanup), it's fully serverless so there's no patching/scaling/uptime to babysit, changes are instant config calls, and the free tier means experimentation is risk-free. Caveats: I need credentials with AmazonCognitoPowerUser, some flows (email verification codes, hosted-UI redirects) need a human in the loop, and IAM/session-token expiry is the usual friction point.

Cognito does have a real developer workflow I could act on, so I didn't stop for that reason — credentials are the only blocker.

AX Fundamentals

23 checks. Open an area for details.

This check is a quick preview. Test more tasks and models with Gauge Agents.

Test your product with Gauge Agents

AX Check by Gauge