Amazon Cognito now enables app clients to specify resource indicators during access token requests as part of its OAuth 2.0 authorization code grant and implicit grant flows. The resource indicator identifies the protected resource, such as a user’s bank account record or a specific file in a file server that the user needs to access. After authenticating the client, Cognito then issues an access token for that specific resource. This ensures that access tokens can be limited from broad service level access down to accessing specific individual resources.
This capability makes it simpler to protect resources that a user needs to access. For example, agents (an example of app clients) on behalf of users can request access tokens for specific protected resources, such as a user’s banking records. After validation, Cognito issues an access token with the audience claim set to the specific resource. Previously, clients had to use non-standard claims or scopes for Cognito to infer and issue resource-specific access tokens. Now, customers can specify the target resource in a simple and consistent way using standards-based resource parameter.
This capability is available to Amazon Cognito Managed Login customers using Essentials or Plus tiers in AWS Regions where Cognito is available, including the AWS GovCloud (US) Regions. To learn more, refer to the developer guide, and pricing for Cognito Essentials and Plus tier.
Categories: general:products/aws-govcloud-us,general:products/amazon-cognito,marketing:marchitecture/security-identity-and-compliance
Source: Amazon Web Services
Latest Posts
- Amazon Redshift Serverless is now available in the AWS Asia Pacific (Osaka) and Asia Pacific (Malaysia) regions

- Dataverse Storage Corrected, No Action Needed [MC1180870]
![Dataverse Storage Corrected, No Action Needed [MC1180870] 3 pexels andre furtado 43594 2916820](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Microsoft Copilot Studio – Add and configure tool groups to agents [MC1180873]
![Microsoft Copilot Studio – Add and configure tool groups to agents [MC1180873] 4 pexels energepic com 27411 313690](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Microsoft Copilot Studio – Automate approvals decisions with Intelligent Approvals [MC1162218]
![Microsoft Copilot Studio – Automate approvals decisions with Intelligent Approvals [MC1162218] 5 drops 3273161 1920](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)


![Dataverse Storage Corrected, No Action Needed [MC1180870] 3 pexels andre furtado 43594 2916820](https://mwpro.co.uk/wp-content/uploads/2025/06/pexels-andre-furtado-43594-2916820-150x150.webp)
![Microsoft Copilot Studio – Add and configure tool groups to agents [MC1180873] 4 pexels energepic com 27411 313690](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-energepic-com-27411-313690-150x150.webp)
![Microsoft Copilot Studio – Automate approvals decisions with Intelligent Approvals [MC1162218] 5 drops 3273161 1920](https://mwpro.co.uk/wp-content/uploads/2025/06/drops-3273161_1920-150x150.webp)
