1 Answer
- Newest
- Most votes
- Most comments
4
Hi, standard and custom attributes will be included in user's id-token. you will need to pass this token to your APIs or backend, verify token signature, decode the token and then manually verify the value of attributes (like subscriptions).
If you are using API Gateway then you need a lambda authorzer, where you can do this token validation and verification of the claims. here is an example of lambda authorizer.
Relevant content
- asked 2 months ago
- AWS OFFICIALUpdated 3 days ago
- AWS OFFICIALUpdated a year ago
- AWS OFFICIALUpdated 9 months ago
- AWS OFFICIALUpdated a year ago
This is specific to amplify API/graphQL, but is this the type of this you are looking for? https://docs.amplify.aws/cli/graphql/authorization-rules/#configure-custom-identity-and-group-claims. If not, add a little more detail to your question, thanks.