AWS Security ChangesHomeSearch

AWS appsync: AppSync: set clientId when JWT issuer is shared/non-unique

Service: appsync · 2026-09-27 · Documentation medium

File: appsync/latest/devguide/security-authz.md · Type: authz

Summary

Adds a note warning that shared issuers such as Cognito identity pools have non-unique issuer URLs, so clientId must be set to restrict access to tokens issued for your own pool or application.

Security assessment

The note documents an authorization hardening step: with a shared issuer URL such as https://cognito-identity.amazonaws.com, omitting clientId would allow tokens issued to other applications/pools to be accepted by the API. It is preventive guidance for a misconfiguration rather than a fix for a specific incident or CVE, so it is security documentation at medium severity.

Evidence

+For shared issuers, such as Amazon Cognito identity pools, the issuer URL (for example, `https://cognito-identity.amazonaws.com`) is not unique to your pool or application. In this case, be sure to set `clientId`, because it restricts access to tokens issued for your pool or application.

Diff

diff --git a/appsync/latest/devguide/security-authz.md b/appsync/latest/devguide/security-authz.md
index 4a1b0184f..0d6d15360 100644
--- a//appsync/latest/devguide/security-authz.md
+++ b//appsync/latest/devguide/security-authz.md
@@ -477,0 +478,4 @@ To validate multiple client IDs use the pipeline operator (“|”) which is an
+###### Note
+
+For shared issuers, such as Amazon Cognito identity pools, the issuer URL (for example, `https://cognito-identity.amazonaws.com`) is not unique to your pool or application. In this case, be sure to set `clientId`, because it restricts access to tokens issued for your pool or application.
+