AWS Cognito自定义域名下/.well-known/openid-configuration端点无法正常访问问题咨询
Great question—this is a super common pitfall when setting up custom domains with AWS Cognito. Let’s walk through the most likely missing steps that could be causing this error:
1. You’re including the user pool ID in the custom domain path (don’t do that!)
This is the #1 mistake people make. Unlike the default Cognito domain (which requires the pool ID in the URL), the custom domain endpoint does NOT need the user pool ID.
- Correct custom domain endpoint:
https://{your-custom-domain}/.well-known/openid-configuration - Incorrect (what you might be accidentally using):
https://{your-custom-domain}/{pool-id}/.well-known/openid-configuration
Double-check the URL you’re accessing—removing the pool ID will fix this for most cases.
2. Verify your DNS CNAME record is properly set up
Cognito custom domains rely on CloudFront under the hood, so you need to point your custom domain’s CNAME record to the CloudFront distribution URL provided by Cognito.
- Go to your Cognito user pool’s Domain name tab, look for the "CloudFront distribution" value (it’ll look like
dxxxxxx.cloudfront.net). - Update your domain’s DNS settings to create a CNAME record that maps your custom domain to this CloudFront URL.
- Wait for DNS propagation (can take 5-30 minutes) and confirm with a tool like
nslookup {your-custom-domain}that it resolves to the correct CloudFront IPs.
3. Ensure your SSL certificate is correctly configured
CloudFront requires SSL certificates to be issued in the us-east-1 (N. Virginia) region of ACM, even if your user pool is in another region.
- Go to ACM in us-east-1, confirm your certificate for the custom domain is Issued and validation is complete (either DNS or email validation).
- In Cognito’s Domain settings, make sure you selected this valid certificate when setting up the custom domain.
4. Check the custom domain’s activation status
After setting up the custom domain in Cognito, it can take a few minutes for the CloudFront distribution to deploy.
- In the Cognito Domain tab, check the status next to your custom domain—it should say Active. If it’s still "In progress", wait for deployment to finish before testing the endpoint.
5. Rule out caching issues
Browser caching or CloudFront’s default cache might be serving old error responses.
- Try accessing the endpoint in an incognito window, or use
curl -v https://{your-custom-domain}/.well-known/openid-configurationto see the raw HTTP response headers and error details. This can help pinpoint if it’s a 404 (path issue), 503 (deployment in progress), or SSL error (certificate problem).
If you’ve gone through all these steps and still see errors, the raw curl output will give you more clues to dig deeper!
内容的提问来源于stack exchange,提问作者alesk

