如何在AWS Cognito中实现Apple Sign In支持?含2020年合规要求咨询
Hey there, let's break down exactly how to integrate Apple Sign In with AWS Cognito. I've implemented this several times for different apps, so I'll walk you through every step with practical details.
技术方案与操作指导:AWS Cognito集成Apple Sign In
一、前期准备(Apple开发者端)
- First off, you’ll need an active Apple Developer账号. Head to the Apple Developer Portal, create an App ID for your app, and enable the "Sign In with Apple" capability for it.
- Generate a server-side private key (you’ll download this as a
.p8file). Make sure to note down two key pieces of info: the Key ID (linked to this private key) and your Apple Team ID (found in your Apple Developer account settings). - Configure the return URL for Sign In with Apple: it needs to be your Cognito user pool domain plus
/oauth2/idpresponse, likehttps://your-user-pool-domain.auth.us-east-1.amazoncognito.com/oauth2/idpresponse. Apple requires this URL to be HTTPS, no extra path parameters allowed.
二、AWS Cognito端配置
1. 添加Apple身份提供者
- Log into the AWS Console, navigate to your Cognito User Pool, go to the Identity Providers tab, and select "Add Apple".
- Fill in the required fields:
- Client ID: Your App ID from the Apple Developer Portal (usually in the format
com.yourcompany.yourapp). - Team ID: Your Apple Developer Team ID.
- Key ID: The ID associated with the private key you generated earlier.
- Private Key: Copy the entire content of the
.p8file you downloaded, including the-----BEGIN PRIVATE KEY-----and-----END PRIVATE KEY-----lines.
- Client ID: Your App ID from the Apple Developer Portal (usually in the format
- Save the identity provider once all fields are confirmed.
2. 更新用户池应用客户端
- Go to the App Clients tab in your Cognito User Pool, edit the app client you want to integrate with Apple Sign In.
- Under Enabled Identity Providers, check the "Apple" option you just added.
- If you’re using OAuth 2.0, make sure to enable the
openidscope (this is mandatory for Apple Sign In to return an ID Token). You can also addemailandprofilescopes if you need user contact/name info. - Double-check that your Callback URL(s) and Sign Out URL(s) match exactly what you configured in the Apple Developer Portal (critical for web apps).
3. 配置属性映射(可选但推荐)
- Back in the Apple Identity Provider settings, find the Attribute Mapping section.
- Map Apple's returned user attributes to Cognito's user pool attributes:
- Map Apple’s
emailto Cognito’semail - Map Apple’s
name.givenNameto Cognito’sgiven_name - Map Apple’s
name.familyNameto Cognito’sfamily_name
- Map Apple’s
- This ensures user data like email and name are automatically populated in your Cognito user pool after sign-in.
三、客户端集成示例(Web应用)
If you’re using AWS Amplify (the easiest way for web apps), here’s a quick code snippet:
import { Auth } from 'aws-amplify'; // Initialize Amplify with your Cognito config Auth.configure({ Auth: { userPoolId: 'your-user-pool-id', userPoolWebClientId: 'your-app-client-id', oauth: { domain: 'your-user-pool-domain.auth.us-east-1.amazoncognito.com', scope: ['openid', 'email', 'profile'], redirectSignIn: 'https://your-app-url.com/signin-callback', redirectSignOut: 'https://your-app-url.com/signout', responseType: 'code' // Recommended for production (authorization code flow) } } }); // Trigger Apple Sign In async function signInWithApple() { try { const user = await Auth.federatedSignIn({ provider: 'Apple' }); console.log('Sign-in successful:', user); } catch (err) { console.error('Sign-in failed:', err); } }
For native iOS apps, use Apple's ASAuthorizationAppleIDButton to initiate the sign-in flow, then pass the resulting ID Token to Cognito's InitiateAuth API. The Amplify iOS library can handle this flow out of the box too.
四、常见问题排查
- "invalid_client" error from Apple: Double-check that your Client ID, Team ID, Key ID, and Private Key in Cognito match exactly what’s in the Apple Developer Portal. Make sure you copied the entire private key (including the header/footer lines).
- No email/name in Cognito user profile: Verify your attribute mappings are set up correctly. Also note that users can choose to hide their email/name during the first Apple Sign In—your app should handle this scenario gracefully.
- Callback URL mismatch: Ensure the return URL in Apple Developer Portal is identical to the callback URL in your Cognito app client (HTTPS, exact path, no typos).
内容的提问来源于stack exchange,提问作者Ted
相关产品推荐
相关产品推荐

