AWS Security ChangesHomeSearch

AWS appsync: AppSync Event API: set clientId for shared JWT issuers

Service: appsync · 2026-09-27 · Documentation medium

File: appsync/latest/eventapi/configure-event-api-auth.md · Type: authz

Summary

Adds the same note for Event API authorization, stating that shared issuer URLs (e.g., Cognito identity pools) are not unique and clientId must be set to restrict token acceptance to your pool or application.

Security assessment

Identical authorization-hardening guidance applied to AppSync Event API auth configuration: an unset clientId with a shared issuer could permit tokens minted for other applications to be accepted, enabling unauthorized access. Documentation-level hardening guidance, not a fix for a named vulnerability.

Evidence

+For shared issuers, such as Amazon Cognito identity pools, the issuer URL (for example, `https://cognito-identity.amazonaws.com`) is not unique to your pool or application. In this case, be sure to set `clientId`, because it restricts access to tokens issued for your pool or application.

Diff

diff --git a/appsync/latest/eventapi/configure-event-api-auth.md b/appsync/latest/eventapi/configure-event-api-auth.md
index 60e04cec2..eb4426969 100644
--- a//appsync/latest/eventapi/configure-event-api-auth.md
+++ b//appsync/latest/eventapi/configure-event-api-auth.md
@@ -325,0 +326,4 @@ To validate multiple client IDs use the pipeline operator (“|”) which is an
+###### Note
+
+For shared issuers, such as Amazon Cognito identity pools, the issuer URL (for example, `https://cognito-identity.amazonaws.com`) is not unique to your pool or application. In this case, be sure to set `clientId`, because it restricts access to tokens issued for your pool or application.
+