What an access token is and why you need one
An access token is a credential that AWS Cognito gives you after you sign in. It proves to your application that you are who you say you are, and it contains information about what you are allowed to do. When your app needs to call an AWS service or your own backend API, you send this token along with the request instead of sending your password every time.
Cognito is AWS's user management service. It handles sign-up, sign-in, and password resets for you, then hands out tokens when authentication succeeds. The access token lasts for a set time — usually one hour by default — and then expires. When it expires, you use a separate refresh token to get a new access token without asking the user to sign in again.
You need an access token because it is far safer than storing passwords in your application. The token is temporary, limited in what it can do, and can be revoked. A password is permanent and gives full access.
Key Takeaways
- Access tokens come from Cognito after a user signs in successfully, and they expire after a set time — usually one hour.
- You get an access token by sending the user's username and password to Cognito's authentication endpoint, or by using a refresh token if the old one expired.
- The token itself is a long string of characters (a JWT) that your app stores and sends with every request that needs authentication.
- You can test token retrieval using the AWS CLI, Postman, or code in your preferred language — each method shows you exactly what Cognito returns.
- Tokens are specific to a Cognito user pool, so you must know your pool ID and client ID before you can request one.
Finding your Cognito user pool ID and client ID
Before you can get an access token, you need two pieces of information from your Cognito setup: the user pool ID and the app client ID. These are identifiers that tell Cognito which user pool you are working with and which application is asking for the token.
Go to the AWS Management Console and open Cognito. Click "User pools" on the left side. Select the user pool you want to work with. On the pool's main page, you will see the pool ID at the top — it looks like us-east-1_abc123def456. Write this down.
Next, click "App integration" in the left menu, then "App clients and analytics". You will see a list of app clients. Click the one you use for your application. On that client's page, you will see the "Client ID" field. This is the second piece of information you need. Copy both the pool ID and client ID into a text file — you will use them in the next steps.
Getting a token using the AWS CLI
The fastest way to test token retrieval is the AWS CLI, which is a command-line tool that talks to AWS services. If you do not have it installed, download it from the AWS website and follow the installation guide for your operating system.
Open your terminal or command prompt and run this command, replacing the placeholders with your actual values:
aws cognito-idp initiate-auth --client-id YOUR_CLIENT_ID --auth-flow USER_PASSWORD_AUTH --auth-parameters USERNAME=testuser,PASSWORD=testpassword --region us-east-1
Replace YOUR_CLIENT_ID with the client ID you copied earlier. Replace testuser and testpassword with the actual username and password of a user in your Cognito pool. Change us-east-1 to the AWS region where your user pool lives if it is different.
If the sign-in succeeds, Cognito returns a JSON response that includes an AccessToken field. That long string of characters is your access token. It is a JWT (JSON Web Token), which means it is encoded but not encrypted — anyone can read what is inside it, but only AWS can create a valid one. Store this token in your application's memory or session, and send it with requests that need authentication.
Getting a token using Postman
Postman is a graphical tool for testing APIs. If you do not have it, download it from the Postman website. Open Postman and create a new request by clicking the "+" button.
Set the request method to POST. In the URL field, enter your Cognito authentication endpoint. The format is:
https://YOUR_POOL_DOMAIN.auth.REGION.amazoncognito.com/oauth2/token
Replace YOUR_POOL_DOMAIN with the domain name you set up in Cognito (found under App integration → Domain name), and replace REGION with your AWS region. Click the "Body" tab, select "form-data", and add these fields:
- grant_type: password
- client_id: your app client ID
- username: the username of the user signing in
- password: the user's password
Click "Send". Cognito returns a JSON response with an access_token field. Copy that token value — it is what you use to authenticate requests in your application.
Getting a token in your application code
In a real application, you do not ask the user to run CLI commands. Instead, your code calls Cognito directly. Here is how to do it in JavaScript using the AWS SDK:
const AWS = require('aws-sdk'); const cognito = new AWS.CognitoIdentityServiceProvider(); const params = { ClientId: 'YOUR_CLIENT_ID', AuthFlow: 'USER_PASSWORD_AUTH', AuthParameters: { USERNAME: 'testuser', PASSWORD: 'testpassword' } }; cognito.initiateAuth(params, (err, data) => { if (err) console.log(err); else console.log(data.AuthenticationResult.AccessToken); });
Replace the client ID, username, and password with real values. When this code runs, it prints the access token to the console. In a production application, you would store this token securely (in memory or a secure cookie) and include it in the Authorization header of API requests.
If you use Python, the boto3 library does the same thing. If you use a different language, the AWS SDK for that language has an equivalent method — look for initiate_auth or InitiateAuth in the documentation.
Using a refresh token to get a new access token
Access tokens expire, usually after one hour. When yours expires, you do not ask the user to sign in again. Instead, you use the refresh token that Cognito gave you at the same time as the access token.
When you first signed in, Cognito returned three tokens: an access token, an ID token, and a refresh token. Store all three. When the access token expires and you need a new one, send the refresh token back to Cognito using the same endpoint:
aws cognito-idp initiate-auth --client-id YOUR_CLIENT_ID --auth-flow REFRESH_TOKEN_AUTH --auth-parameters REFRESH_TOKEN=your_refresh_token --region us-east-1
Replace your_refresh_token with the refresh token you stored earlier. Cognito returns a new access token without requiring the user to sign in. The refresh token itself does not expire (unless you set it to), so you can use it many times over days or weeks.
Troubleshooting common problems
If you get an error saying "Client does not support this auth flow", it means USER_PASSWORD_AUTH is not turned on for your app client. Go to Cognito, find your app client, click "Show Details", scroll to "Authentication Flows Configuration", and check the box next to "ALLOW_USER_PASSWORD_AUTH". Save the changes and try again.
If you get "Invalid client id", double-check that you copied the client ID correctly and that it matches the app client you are trying to use. Client IDs are long strings and easy to mistype.
If you get "User does not exist in the system", the username does not match any user in your Cognito pool. Create a test user in Cognito first, or use the username of a user you know exists.
If the token works but requests still fail, the problem is usually in how you are sending the token. Most APIs expect it in the Authorization header in this format: Authorization: Bearer YOUR_ACCESS_TOKEN. Check your API's documentation to confirm the exact format it expects.
Frequently Asked Questions
How long does an access token last?
By default, one hour. You can change this in Cognito by going to your user pool, clicking "App integration" → "App clients", selecting your client, and editing the "Access token expiration" field. You can set it to any value between 5 minutes and 24 hours.
Can I use the same access token for multiple requests?
Yes. Once you have a token, use it for as many requests as you want until it expires. Store it in memory or a secure cookie and include it in the Authorization header of every request that needs authentication. When it expires, use the refresh token to get a new one.
What happens if I send an expired token?
The API rejects the request and returns an error, usually "Unauthorized" or "Token expired". Your application should catch this error, use the refresh token to get a new access token, and retry the request automatically.
Is the access token encrypted?
No. It is a JWT, which is encoded but not encrypted. Anyone can decode it and read what is inside. However, only AWS can create a valid token, so an attacker cannot forge one. Always send tokens over HTTPS so they cannot be intercepted in transit.
Do I need to store the access token in a database?
No. The token is temporary and stateless — Cognito does not need to look it up anywhere. Your application stores it in memory or a session while the user is active, and discards it when the user signs out or the token expires.