You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在AWS Cognito中实现Apple Sign In支持?含2020年合规要求咨询

Hey there, let's break down exactly how to integrate Apple Sign In with AWS Cognito. I've implemented this several times for different apps, so I'll walk you through every step with practical details.

技术方案与操作指导:AWS Cognito集成Apple Sign In

一、前期准备(Apple开发者端)

  • First off, you’ll need an active Apple Developer账号. Head to the Apple Developer Portal, create an App ID for your app, and enable the "Sign In with Apple" capability for it.
  • Generate a server-side private key (you’ll download this as a .p8 file). Make sure to note down two key pieces of info: the Key ID (linked to this private key) and your Apple Team ID (found in your Apple Developer account settings).
  • Configure the return URL for Sign In with Apple: it needs to be your Cognito user pool domain plus /oauth2/idpresponse, like https://your-user-pool-domain.auth.us-east-1.amazoncognito.com/oauth2/idpresponse. Apple requires this URL to be HTTPS, no extra path parameters allowed.

二、AWS Cognito端配置

1. 添加Apple身份提供者

  • Log into the AWS Console, navigate to your Cognito User Pool, go to the Identity Providers tab, and select "Add Apple".
  • Fill in the required fields:
    • Client ID: Your App ID from the Apple Developer Portal (usually in the format com.yourcompany.yourapp).
    • Team ID: Your Apple Developer Team ID.
    • Key ID: The ID associated with the private key you generated earlier.
    • Private Key: Copy the entire content of the .p8 file you downloaded, including the -----BEGIN PRIVATE KEY----- and -----END PRIVATE KEY----- lines.
  • Save the identity provider once all fields are confirmed.

2. 更新用户池应用客户端

  • Go to the App Clients tab in your Cognito User Pool, edit the app client you want to integrate with Apple Sign In.
  • Under Enabled Identity Providers, check the "Apple" option you just added.
  • If you’re using OAuth 2.0, make sure to enable the openid scope (this is mandatory for Apple Sign In to return an ID Token). You can also add email and profile scopes if you need user contact/name info.
  • Double-check that your Callback URL(s) and Sign Out URL(s) match exactly what you configured in the Apple Developer Portal (critical for web apps).

3. 配置属性映射(可选但推荐)

  • Back in the Apple Identity Provider settings, find the Attribute Mapping section.
  • Map Apple's returned user attributes to Cognito's user pool attributes:
    • Map Apple’s email to Cognito’s email
    • Map Apple’s name.givenName to Cognito’s given_name
    • Map Apple’s name.familyName to Cognito’s family_name
  • This ensures user data like email and name are automatically populated in your Cognito user pool after sign-in.

三、客户端集成示例(Web应用)

If you’re using AWS Amplify (the easiest way for web apps), here’s a quick code snippet:

import { Auth } from 'aws-amplify';

// Initialize Amplify with your Cognito config
Auth.configure({
  Auth: {
    userPoolId: 'your-user-pool-id',
    userPoolWebClientId: 'your-app-client-id',
    oauth: {
      domain: 'your-user-pool-domain.auth.us-east-1.amazoncognito.com',
      scope: ['openid', 'email', 'profile'],
      redirectSignIn: 'https://your-app-url.com/signin-callback',
      redirectSignOut: 'https://your-app-url.com/signout',
      responseType: 'code' // Recommended for production (authorization code flow)
    }
  }
});

// Trigger Apple Sign In
async function signInWithApple() {
  try {
    const user = await Auth.federatedSignIn({ provider: 'Apple' });
    console.log('Sign-in successful:', user);
  } catch (err) {
    console.error('Sign-in failed:', err);
  }
}

For native iOS apps, use Apple's ASAuthorizationAppleIDButton to initiate the sign-in flow, then pass the resulting ID Token to Cognito's InitiateAuth API. The Amplify iOS library can handle this flow out of the box too.

四、常见问题排查

  • "invalid_client" error from Apple: Double-check that your Client ID, Team ID, Key ID, and Private Key in Cognito match exactly what’s in the Apple Developer Portal. Make sure you copied the entire private key (including the header/footer lines).
  • No email/name in Cognito user profile: Verify your attribute mappings are set up correctly. Also note that users can choose to hide their email/name during the first Apple Sign In—your app should handle this scenario gracefully.
  • Callback URL mismatch: Ensure the return URL in Apple Developer Portal is identical to the callback URL in your Cognito app client (HTTPS, exact path, no typos).

内容的提问来源于stack exchange,提问作者Ted

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.14 09:01:46