You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何编写Python代码获取AWS Cognito访问令牌?代码调试求助

Problem: Python requests POST to Cognito token endpoint doesn't return status code

I have a working Postman POST request to get an access token from Amazon Cognito. The request URL is phmo-test/auth.us-east-1.amazoncognito.com/oauth2/token?grant_type=client_credentials, using Client ID and Client Secret for authorization. When I convert this to Python requests code, the script doesn't return a status code at all. Here's my code:

base_url = 'http://phmo-test.auth.us-east-1.amazoncognito.com/oauth2/token'
client_id=<my client ID>
client_secret=<My client secret>
grant_type='client_credentials'
headers = {'Content-Type':'application/x-www-form-urlencoded', 'cookie':'XSRF-TOKEN=27293445-d70d-4907-bfc5-62ba8a84697c'}
response = requests.post(base_url, auth={'Username':client_id, 'Password':client_secret}, params={'grant_type':grant_type}, headers = headers)
print("WAHHHHHHHHHHHHHHHHHHH",response.status_code)

What am I doing wrong?


Answer

Let's walk through the issues in your code that are blocking you from getting a valid response status code:

  • Wrong URL protocol: Amazon Cognito's APIs exclusively use HTTPS. Using http:// will either make your request hang indefinitely (since Cognito doesn't listen on HTTP ports) or fail silently—this is almost certainly why you're not seeing any status code at all. Switch to https:// for the base URL.

  • Incorrect auth parameter format: For Cognito's Client Credentials flow, you need to use HTTP Basic Authentication. The requests.post() method expects the auth parameter to be a tuple of (client_id, client_secret), not a dictionary with Username and Password keys. The dictionary format is meant for other auth schemes (like Digest Auth) and won't work here.

  • Unnecessary XSRF cookie: The XSRF-TOKEN cookie is only required for browser-based flows (like Authorization Code with PKCE). For server-to-server Client Credentials flow, this cookie is irrelevant and can be removed entirely—it might even cause unexpected validation issues.

  • Grant type in the wrong place: The grant_type=client_credentials should be sent as form-encoded data in the request body, not as a URL query parameter. Even if your Postman request had it in the URL, Cognito expects this parameter in the body for this flow. Use the data parameter instead of params.

Here's the fixed code:

import requests

base_url = 'https://phmo-test.auth.us-east-1.amazoncognito.com/oauth2/token'
client_id = '<your client ID>'
client_secret = '<your client secret>'
grant_type = 'client_credentials'

# Only keep the necessary Content-Type header
headers = {'Content-Type': 'application/x-www-form-urlencoded'}

response = requests.post(
    base_url,
    auth=(client_id, client_secret),
    data={'grant_type': grant_type},
    headers=headers
)

print("Status Code:", response.status_code)
# Add this to debug any error messages from Cognito
print("Response Details:", response.json())

If you still hit issues after these changes, double-check that your Cognito app client is configured to allow the Client Credentials flow (make sure the flow is enabled in the app client settings and the client has the appropriate permissions for your resources).

内容的提问来源于stack exchange,提问作者user8882700

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.13 07:50:24