AWS Cognito用户仍存在却报NotAuthorizedException异常咨询
Hey there, let's unpack this confusing situation you're facing. You've confirmed the user exists in AWS Cognito, but you're getting a NotAuthorizedException: The user has been deleted for the associated refresh token error when using their refresh token. Here's what's going on and why this mismatch might be happening:
What This Exception Actually Means
At face value, the error says the refresh token you’re trying to use is linked to a user that no longer exists in Cognito. But since you’ve verified the user does exist, this points to a mismatch between the token’s embedded identity and the user you’re seeing in your pool.
Why This Happens (Even When the User Exists)
The most common culprits tie directly to how Cognito identifies users and manages tokens:
- You recreated a user with the same username after deleting them: Cognito uses a unique
sub(subject) ID as the primary user identifier—not the username. If you deleted a user then created a new one with the exact same username, the new user gets a completely differentsubID. The old refresh token is still tied to the deleted user’ssub, so Cognito sees it as invalid (since that original user is gone). - The refresh token was issued for a different user instance: Even if you didn’t intentionally delete the user, there might have been a scenario where the user was removed and restored (e.g., via automated scripts or accidental deletion) with a new
sub. The existing refresh token won’t recognize this new user instance. - Rare: Cognito cache or configuration glitches: In edge cases, Cognito’s internal cache might be out of sync, showing the user as existing but still checking against an old record. This is far less common, but worth ruling out.
How to Resolve It
Here’s what you can do to fix this:
- Decode the refresh token to check its
subclaim: Use a JWT decoder (you can do this locally with libraries likejsonwebtokenin Node.js, or even a simple offline tool) to pull thesubvalue from the token. Then go to your Cognito user pool, find the existing user, and compare theirsubID. If they don’t match, the token belongs to a deleted user—your only fix is to have the user re-authenticate to get a new refresh token tied to the current user’ssub. - Check user deletion history: Review your Cognito user pool’s audit logs to see if the user was ever deleted and recreated. If that’s the case, old tokens are permanently invalid for the new user.
- Verify token validity and revocation status: Double-check that the refresh token hasn’t expired (check your app client’s token expiration settings) and hasn’t been revoked manually in the user’s Cognito details. While this usually throws a different error, it’s worth eliminating as a possibility.
内容的提问来源于stack exchange,提问作者Shashwat Tripathi

