# Configure Cognito Identity Pool in Serverless

**URL:** <https://discourse.sst.dev/t/configure-cognito-identity-pool-in-serverless/165>\
**Category:** Chapter Comments\
**Created:** [May 9, 2018, 11:15pm UTC](https://discourse.sst.dev/t/configure-cognito-identity-pool-in-serverless/165 "2018-05-09T23:15:31Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![jayair](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.sst.dev/jayair/32/9_2.png) [@jayair](https://discourse.sst.dev/u/jayair)\
**Post date:** [May 9, 2018, 11:15pm UTC](https://discourse.sst.dev/t/configure-cognito-identity-pool-in-serverless/165/1 "2018-05-09T23:15:31Z")

</div>

Link to chapter - [https://serverless-stack.com/chapters/configure-cognito-identity-pool-in-serverless.html](https://serverless-stack.com/chapters/configure-cognito-identity-pool-in-serverless.html)

---

<div class="post-metadata">

**Author:** ![pobch](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.sst.dev/pobch/32/312_2.png) [@pobch](https://discourse.sst.dev/u/pobch)\
**Post date:** [October 29, 2018, 10:30pm UTC](https://discourse.sst.dev/t/configure-cognito-identity-pool-in-serverless/165/2 "2018-10-29T22:30:35Z")

</div>

Can we use `Ref: ApiGatewayRestApi` even we’ve not defined `ApiGatewayRestApi`?

---

<div class="post-metadata">

**Author:** ![jayair](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.sst.dev/jayair/32/9_2.png) [@jayair](https://discourse.sst.dev/u/jayair)\
**Post date:** [October 30, 2018, 9:17pm UTC](https://discourse.sst.dev/t/configure-cognito-identity-pool-in-serverless/165/3 "2018-10-30T21:17:51Z")

</div>

I should probably add a note on this. The `ApiGatewayRestApi` is a name that Serverless Framework uses to name the API Gateway resource that is defined in the `serverless.yml`.

---

<div class="post-metadata">

**Author:** ![amoses12](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.sst.dev/amoses12/32/675_2.png) [@amoses12](https://discourse.sst.dev/u/amoses12)\
**Post date:** [December 6, 2018, 10:42pm UTC](https://discourse.sst.dev/t/configure-cognito-identity-pool-in-serverless/165/4 "2018-12-06T22:42:28Z")

</div>

An Identity Pool seems to require an UnAuth role as well as an Auth Role. How is the UnAuth role handled in a .yml file?

---

<div class="post-metadata">

**Author:** ![jayair](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.sst.dev/jayair/32/9_2.png) [@jayair](https://discourse.sst.dev/u/jayair)\
**Post date:** [December 7, 2018, 12:17am UTC](https://discourse.sst.dev/t/configure-cognito-identity-pool-in-serverless/165/5 "2018-12-07T00:17:16Z")

</div>

Are you seeing any errors? We don’t set the Unauth role. But we have this at the top `AllowUnauthenticatedIdentities: false`.

---

<div class="post-metadata">

**Author:** ![amoses12](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.sst.dev/amoses12/32/675_2.png) [@amoses12](https://discourse.sst.dev/u/amoses12)\
**Post date:** [December 7, 2018, 3:28pm UTC](https://discourse.sst.dev/t/configure-cognito-identity-pool-in-serverless/165/6 "2018-12-07T15:28:19Z")

</div>

Thanks for the response. I have that line in my yaml file, but when I log in to the console and look at my identity pool, It still tells me that I need to attach an unauthorized role policy. I figured out how to add the unauth policy in the yaml file, but for future reference Is that warning in the AWS console something I can just ignore?

---

<div class="post-metadata">

**Author:** ![jayair](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.sst.dev/jayair/32/9_2.png) [@jayair](https://discourse.sst.dev/u/jayair)\
**Post date:** [December 9, 2018, 7:53pm UTC](https://discourse.sst.dev/t/configure-cognito-identity-pool-in-serverless/165/7 "2018-12-09T19:53:59Z")

</div>

Oh yeah, you don’t need to. By configuring our infrastructure as code, you don’t need to check the console.

---

<div class="post-metadata">

**Author:** ![HannahStahl](https://avatars.discourse-cdn.com/v4/letter/h/ed655f/32.png) [@HannahStahl](https://discourse.sst.dev/u/HannahStahl)\
**Post date:** [January 3, 2019, 1:51am UTC](https://discourse.sst.dev/t/configure-cognito-identity-pool-in-serverless/165/8 "2019-01-03T01:51:09Z")

</div>

How would I go about allowing unauthenticated read-only access to the files in the s3 attachments bucket? I still want only authenticated users to be able to upload files (as the current code has it), but I also want unauthenticated users to be able to fetch files from the s3 bucket. Thanks in advance.

---

<div class="post-metadata">

**Author:** ![jayair](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.sst.dev/jayair/32/9_2.png) [@jayair](https://discourse.sst.dev/u/jayair)\
**Post date:** [January 6, 2019, 3:38am UTC](https://discourse.sst.dev/t/configure-cognito-identity-pool-in-serverless/165/9 "2019-01-06T03:38:23Z")

</div>

So the URLs that we generate are publicly accessible AFAIK. Can you give that a try?

---

<div class="post-metadata">

**Author:** ![HannahStahl](https://avatars.discourse-cdn.com/v4/letter/h/ed655f/32.png) [@HannahStahl](https://discourse.sst.dev/u/HannahStahl)\
**Post date:** [January 9, 2019, 5:32pm UTC](https://discourse.sst.dev/t/configure-cognito-identity-pool-in-serverless/165/10 "2019-01-09T17:32:20Z")

</div>

Yes, it appears the URLs are publicly accessible. In terms of actually generating those URLs though, I wouldn’t want to use the aws-amplify “Storage.get.vault(…)” method (since it involves authentication), right? How would I go about it in an unauthenticated way?

UPDATE:

Got it to work by doing s3 = AWS.S3(…) with credentials I put in an .env file, and then s3.getSignedUrl(…) with the s3 bucket name and file key.

---

<div class="post-metadata">

**Author:** ![jayair](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.sst.dev/jayair/32/9_2.png) [@jayair](https://discourse.sst.dev/u/jayair)\
**Post date:** [January 14, 2019, 7:34pm UTC](https://discourse.sst.dev/t/configure-cognito-identity-pool-in-serverless/165/11 "2019-01-14T19:34:14Z")

</div>

Glad you figured it out. Thanks for the update.

---

<div class="post-metadata">

**Author:** ![hmpargi](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.sst.dev/hmpargi/32/486_2.png) [@hmpargi](https://discourse.sst.dev/u/hmpargi)\
**Post date:** [May 7, 2019, 1:05am UTC](https://discourse.sst.dev/t/configure-cognito-identity-pool-in-serverless/165/12 "2019-05-07T01:05:47Z")

</div>

![unauthenticated](https://canada1.discourse-cdn.com/flex032/uploads/serverless_stack/original/1X/d091c44c8405a4f1a0d043c6933bd1bb977c8b34.jpeg)

Once I deploy Autmation Serverless Backend API I checked identity pool error in aws console. After reading this post looks like we can ignore it correct ?

---

<div class="post-metadata">

**Author:** ![jayair](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.sst.dev/jayair/32/9_2.png) [@jayair](https://discourse.sst.dev/u/jayair)\
**Post date:** [May 27, 2019, 12:12am UTC](https://discourse.sst.dev/t/configure-cognito-identity-pool-in-serverless/165/13 "2019-05-27T00:12:30Z")

</div>

Yeah you should be okay.

---

<div class="post-metadata">

**Author:** ![ryanauj](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.sst.dev/ryanauj/32/838_2.png) [@ryanauj](https://discourse.sst.dev/u/ryanauj)\
**Post date:** [April 26, 2020, 4:29am UTC](https://discourse.sst.dev/t/configure-cognito-identity-pool-in-serverless/165/14 "2020-04-26T04:29:01Z")

</div>

Is there a reason that the `IdentityPoolName` value is using upper camel / pascal case, i.e.

```auto
IdentityPoolName: ${self:custom.stage}IdentityPool

```

whereas the `UserPoolName` is hyphen-separated, i.e.

```auto
UserPoolName: ${self:custom.stage}-user-pool

```

?

Sorry, I know this is kind of nitpicky, but I was just wondering if it was a style convention for each of these resources.

---

<div class="post-metadata">

**Author:** ![cemozer](https://avatars.discourse-cdn.com/v4/letter/c/46a35a/32.png) [@cemozer](https://discourse.sst.dev/u/cemozer)\
**Post date:** [April 28, 2020, 4:18am UTC](https://discourse.sst.dev/t/configure-cognito-identity-pool-in-serverless/165/15 "2020-04-28T04:18:31Z")

</div>

Hi, first of all, I’m a huge fan of this tutorial so thank you very much. I’m curious if I can share a cognito-identity-pool among two API gateways. I created an app using this tutorial, and now to increase its features, I want to add a micro-service with a dynamoDB instance and API’s to write to it.

For that, I copied the directory of the serverless tutorial backend, and stripped off the cognito and s3 resources, and only kept the new dynamoDB resource and the api-gateway-errors YAML file. When I use the aws-api-gateway-cli-test for this new service while specifying the user-pool-id of the old app, I get an error like this:

```auto
    { status: 403,
  statusText: 'Forbidden',
  data:
   { message:
      'User: arn:aws:sts::259875073853:assumed-role/medbuddy-api-dev-CognitoAuthRole-1UD5GTTQXS920/CognitoIdentityCredentials is not authorized to perform: execute-api:Invoke on resource: arn:aws:execute-api:us-east-1: ******** 3853:qd9g63v59g/dev/POST/medications' } }

```

I came to the conclusion that I have to specify somewhere in the new microservices serverless or cloud formation files to connect to the existing user-pool-id of the previous stack, but can’t figure out how to do that. I would really appreciate some help. Thank you.

---

<div class="post-metadata">

**Author:** ![jayair](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.sst.dev/jayair/32/9_2.png) [@jayair](https://discourse.sst.dev/u/jayair)\
**Post date:** [May 3, 2020, 12:57am UTC](https://discourse.sst.dev/t/configure-cognito-identity-pool-in-serverless/165/16 "2020-05-03T00:57:31Z")

</div>

No there isn’t really. You can them any which way you like.

---

<div class="post-metadata">

**Author:** ![jayair](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.sst.dev/jayair/32/9_2.png) [@jayair](https://discourse.sst.dev/u/jayair)\
**Post date:** [May 3, 2020, 1:06am UTC](https://discourse.sst.dev/t/configure-cognito-identity-pool-in-serverless/165/17 "2020-05-03T01:06:21Z")

</div>

Thanks!

In the original Identity Pool, we allow access to our API Gateway by doing this:

> <https://github.com/AnomalyInnovations/serverless-stack-demo-api/blob/master/resources/cognito-identity-pool.yml#L67>

You’ll need to do something similar for your new API.

Though I would question if you need a completely new endpoint or if you can add another service but use the same endpoint. Say `/notes` and `/users` or something.

---

<div class="post-metadata">

**Author:** ![cemozer](https://avatars.discourse-cdn.com/v4/letter/c/46a35a/32.png) [@cemozer](https://discourse.sst.dev/u/cemozer)\
**Post date:** [May 3, 2020, 4:08am UTC](https://discourse.sst.dev/t/configure-cognito-identity-pool-in-serverless/165/18 "2020-05-03T04:08:35Z")

</div>

I’ve decided adding another endpoint is way easier to work with, thanks for the tip.

One issue I’m having with the Serverless stack is though, every time I make changes to the back-end (APIs), I have to redeploy the whole stack and all the existing user pools and databases become obsolete. I can’t imagine this being the case in a production environment. How do you transfer all the users and their content on to the new serverless stack? or should I be modifying my update process so that I don’t overwrite the existing stack? (in that case how do I do that? 😃, with seed.run I feel like I can’t edit the serverless deploy call and so I’m stuck with rewriting the whole existing stack)

---

<div class="post-metadata">

**Author:** ![jayair](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.sst.dev/jayair/32/9_2.png) [@jayair](https://discourse.sst.dev/u/jayair)\
**Post date:** [May 3, 2020, 5:15pm UTC](https://discourse.sst.dev/t/configure-cognito-identity-pool-in-serverless/165/19 "2020-05-03T17:15:15Z")

</div>

What do you mean obsolete? If you change the service name in your `serverless.yml` it’ll create a completely new stack. Otherwise it should simply update your existing stack.

---

<div class="post-metadata">

**Author:** ![cemozer](https://avatars.discourse-cdn.com/v4/letter/c/46a35a/32.png) [@cemozer](https://discourse.sst.dev/u/cemozer)\
**Post date:** [May 3, 2020, 7:37pm UTC](https://discourse.sst.dev/t/configure-cognito-identity-pool-in-serverless/165/20 "2020-05-03T19:37:27Z")

</div>

What has been happening to me is that, every time I change something in the lambdas, the `serverless.yml`, or the resources, it tries to create a total new stack and and complains that I have a dynamoDB or s3 bucket with the same name. After I delete those resources, it creates a completely new stack. What do you think I could be doing wrong that it doesn’t update the stack but re-writes it?

[Next page](https://discourse.sst.dev/t/configure-cognito-identity-pool-in-serverless/165.md?page=2)
