1 Answer
- Newest
- Most votes
- Most comments
0
Calling AdminDisableUser in Amazon Cognito does not immediately revoke all previously issued access tokens. It prevents the user from authenticating again and invalidates refresh tokens going forward, but any already issued access tokens remain valid until they expire. To actively revoke tokens in real time, you may consider using Cognito token revocation features (e.g., RevokeToken API) with token revocation enabled on your app client.
https://docs.aws.amazon.com/cognito/latest/developerguide/token-revocation.html
https://docs.aws.amazon.com/cognito/latest/developerguide/token-revocation.html
