Amazon Cognito

AWSSecurityFree tier available

Customer identity and access management service with User Pools for sign-up and sign-in, Identity Pools for federated AWS credentials, social and SAML/OIDC federation, hosted UI, adaptive authentication, and advanced security risk scoring for consumer-scale apps

Jurisdictional exposure

Provider HQ
USSeattle, USA

Subject to CLOUD Act, FISA-702, DPF

Region locations
APACCNEEAEUUKUSOther40 regions across 7 jurisdictions
Sovereign option
Yes — 6 sovereign-flagged regions available

Attributes

SLA Uptime
99.9%
Mfa Support
Yes

Sub-services (4)

User Pools

User directory with sign-up, sign-in, MFA, social and SAML/OIDC federation

Identity Pools

Exchange verified identities for temporary AWS credentials for mobile and web apps

Hosted UI

Customisable AWS-managed sign-in and sign-up pages with OAuth 2.0 and OIDC

Advanced Security

Compromised-credentials detection, risk-based adaptive MFA, and anomaly alerts

Compliance & Certifications

This service is attested for the following frameworks. Always verify with the provider before relying on a specific compliance posture.

Where this runs

40 regions
28 countries
6sovereign
Sovereign regions (6)
  • AWS European Sovereign Cloud (Brandenburg) · BrandenburgAWS European Sovereign Cloud
  • AWS GovCloud (US-East) · AshburnAWS GovCloud (US)
  • AWS GovCloud (US-West) · HillsboroAWS GovCloud (US)
  • AWS European Sovereign Cloud (Brandenburg) · BrandenburgAWS European Sovereign Cloud
  • China (Beijing) · BeijingAWS China (Sinnet)
  • China (Ningxia) · YinchuanAWS China (NWCD)
Commercial regions (34)

Europe (8)

  • Europe (Paris)
  • Europe (Frankfurt)
  • Europe (Ireland)
  • Europe (Milan)
  • Europe (Spain)
  • Europe (Stockholm)
  • Europe (Zurich)
  • Europe (London)

North America (7)

  • Canada West (Calgary)
  • Canada (Central)
  • Mexico (Central)
  • US East (N. Virginia)
  • US West (Oregon)
  • US East (Ohio)
  • US West (N. California)

South America (1)

  • South America (São Paulo)

Asia (11)

  • Asia Pacific (Hong Kong)
  • Asia Pacific (Hyderabad)
  • Asia Pacific (Mumbai)
  • Asia Pacific (Jakarta)
  • Asia Pacific (Osaka)
  • Asia Pacific (Tokyo)
  • Asia Pacific (Malaysia)
  • Asia Pacific (Singapore)
  • Asia Pacific (Seoul)
  • Asia Pacific (Taipei)
  • Asia Pacific (Thailand)

Oceania (3)

  • Asia Pacific (Melbourne)
  • Asia Pacific (Sydney)
  • Asia Pacific (New Zealand)

Middle East (3)

  • Middle East (Bahrain)
  • Israel (Tel Aviv)
  • Middle East (UAE)

Africa (1)

  • Africa (Cape Town)

Tags

Equivalent services on other platforms

Alibaba Resource Access ManagementAlibaba

Alibaba Cloud's identity and access management service with users, groups, roles, fine-grained JSON policies, SAML 2.0 federation to enterprise IdPs, and Security Token Service for temporary credentials

Microsoft Entra IDAzure

Cloud identity and access management (formerly Azure AD) with SSO, MFA, conditional access, B2B and B2C guest accounts, and privileged identity management

Microsoft Entra Verified IDAzure

Decentralised identity service that issues and verifies W3C-standard Verifiable Credentials anchored to the ION DID network, enabling passwordless onboarding, employee verification, and credential sharing between organisations without a central identity provider

Cloud IAMGCP

Fine-grained identity and access management with predefined and custom roles, service accounts, workload identity federation, and audit logging

Huawei Identity and Access ManagementHuawei

Centralised identity management for Huawei Cloud with users, user groups, role-based and fine-grained policies, federated identity via SAML/OIDC, MFA, and temporary credentials through Security Token Service

OpenStack KeystoneOpenStack

Identity, authentication, and service-catalogue service — issues tokens, manages users and projects, federates with external identity providers (LDAP, SAML, OIDC), and exposes the service catalogue every other OpenStack project consumes for endpoint discovery

OCI Identity DomainsOracle

Enterprise identity-as-a-service covering workforce and customer identity with federation (SAML, OIDC), social sign-in, MFA, risk-based adaptive authentication, and delegated administration — the rebranded OCI IAM Identity Cloud Service

Tencent Cloud Access ManagementTencent

Tencent Cloud's identity and access management service with sub-accounts, user groups, roles, fine-grained JSON policies, SAML and OIDC federation, MFA, temporary credentials via Security Token Service, and cross-account role assumption

Pricing

Pricing model:pay-per-mau