You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用AWS Cognito验证JWT Token时抛出400错误

AWS Cognito Access Token验证400错误排查

你在SpringBoot中集成AWS Cognito时,登录能正常获取Access Token和ID Token,但验证阶段请求JWKS地址返回400错误,报错如下:

Caused by: java.io.IOException: Server returned HTTP response code: 400 for URL: https://cognito-idp.{region}.amazonaws.com/{poolid}/.well-known/jwks.json
    at java.base/sun.net.www.protocol.http.HttpURLConnection.getInputStream0(HttpURLConnection.java:1997)
    at java.base/sun.net.www.protocol.http.HttpURLConnection.getInputStream(HttpURLConnection.java:1589)
    at java.base/sun.net.www.protocol.https.HttpsURLConnectionImpl.getInputStream(HttpsURLConnectionImpl.java:224)
    at com.nimbusds.jose.util.DefaultResourceRetriever.getInputStream(DefaultResourceRetriever.java:305)
    at com.nimbusds.jose.util.DefaultResourceRetriever.retrieveResource(DefaultResourceRetriever.java:257)
    at com.nimbusds.jose.jwk.source.RemoteJWKSet.updateJWKSetFromURL(RemoteJWKSet.java:305)

可以按以下步骤排查:

  • 修正JWKS URL格式:确保URL中的{region}(如us-east-1)和{poolid}(如us-east-1_abc123)是实际的用户池区域和ID,不能保留占位符。Cognito JWKS的标准格式为https://cognito-idp.{region}.amazonaws.com/{userPoolId}/.well-known/jwks.json。
  • 校验用户池ID有效性:登录AWS控制台进入Cognito用户池,确认配置中使用的用户池ID与实际一致,避免复制时出现空格或字符错误。
  • 测试网络连通性:在应用服务器上执行curl -v https://cognito-idp.{region}.amazonaws.com/{poolid}/.well-known/jwks.json,检查是否能正常返回JSON数据。若无法访问,需排查防火墙、安全组是否允许出站访问该域名的443端口。
  • 配置Nimbus库的资源获取器:如果使用Nimbus JOSE/JWT库,若应用需通过代理访问外部服务,需为DefaultResourceRetriever设置代理参数:
    DefaultResourceRetriever retriever = new DefaultResourceRetriever(10000, 10000);
    retriever.setProxy(new Proxy(Proxy.Type.HTTP, new InetSocketAddress("代理地址", 端口)));
    RemoteJWKSet<SecurityContext> jwkSet = new RemoteJWKSet<>(new URL(jwksUrl), retriever);
    
  • 确认用户池状态:检查Cognito用户池是否处于激活状态,未被禁用或删除。

内容的提问来源于stack exchange,提问作者max v

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.19 19:35:21