# AWS Auth (agent skill)

> AWS Auth is an agent skill (a SKILL.md file) from aws/agent-toolkit-for-aws. It adds user authentication to web and mobile apps with Amazon Cognito (user pools and identity pools) and the AWS Amplify client auth libraries. It works with Claude Code, Codex and Cursor and has 2,816 GitHub stars across a repository of 3 listed skills.

Adds user authentication to web and mobile apps with Amazon Cognito (user pools and identity pools) and the AWS Amplify client auth libraries. Covers sign-up/sign-in flows and the login page (Cognito-hosted UI / managed login), MFA, password policies, OAuth 2.0 / OIDC flows (auth-code + PKCE, client credentials), social/SAML federation, tokens (ID/access/refresh, rotation, revocation, storage), Cognito Lambda triggers, identity pools (temp AWS creds), and gating API Gateway (or ALB) routes to…

## Key facts

| Fact | Value |
|---|---|
| Repository | https://github.com/aws/agent-toolkit-for-aws |
| Skill path | skills/core-skills/aws-auth/SKILL.md |
| Skill name | aws-auth |
| GitHub stars | 2,816 |
| Installs on skills.sh | not listed |
| License | Apache-2.0 |
| Skills in repo | 3 |
| Plugin marketplace | agent-toolkit-for-aws |
| Official | yes |
| Works with | Claude Code, Codex, Cursor |
| Category | Security |
| Last commit | Oct 6, 2026 |

## When it triggers

- user pool or app client, choosing user pool vs identity pool, wiring social/SAML, refreshing tokens, requiring sign-in on an API Gateway or ALB, or debugging redirect_uri/token/MFA/CORS/federation errors.

## Add this skill

### Claude Code

```sh
/plugin marketplace add aws/agent-toolkit-for-aws
/plugin   # browse agent-toolkit-for-aws and install the plugin that contains aws-auth
```

In the Claude apps, zip the skill folder and upload it under Customize > Skills > + > Upload a skill (code execution must be on).

### ChatGPT / Codex

```sh
git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git
cp -r agent-toolkit-for-aws/skills/core-skills/aws-auth .agents/skills/aws-auth   # repo; ~/.agents/skills for all projects
```

### Cursor

```sh
git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git
cp -r agent-toolkit-for-aws/skills/core-skills/aws-auth .cursor/skills/aws-auth   # project; ~/.cursor/skills for all projects
```

Sources (checked 2026-10-07): https://code.claude.com/docs/en/skills, https://support.claude.com/en/articles/12512180-using-skills-in-claude, https://learn.chatgpt.com/docs/build-skills, https://cursor.com/docs/context/skills

---

Canonical page: https://appsgit.com/skills/aws-auth
Source: appsgit (https://appsgit.com), the app store for github. Data from the GitHub API, refreshed nightly.
Machine access: JSON API https://appsgit.com/api/v1/apps (OpenAPI: https://appsgit.com/openapi.json), MCP server https://mcp.appsgit.com/mcp, full index https://appsgit.com/llms-full.txt.
