You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS Cognito用户仍存在却报NotAuthorizedException异常咨询

Hey there, let's unpack this confusing situation you're facing. You've confirmed the user exists in AWS Cognito, but you're getting a NotAuthorizedException: The user has been deleted for the associated refresh token error when using their refresh token. Here's what's going on and why this mismatch might be happening:

What This Exception Actually Means

At face value, the error says the refresh token you’re trying to use is linked to a user that no longer exists in Cognito. But since you’ve verified the user does exist, this points to a mismatch between the token’s embedded identity and the user you’re seeing in your pool.

Why This Happens (Even When the User Exists)

The most common culprits tie directly to how Cognito identifies users and manages tokens:

  • You recreated a user with the same username after deleting them: Cognito uses a unique sub (subject) ID as the primary user identifier—not the username. If you deleted a user then created a new one with the exact same username, the new user gets a completely different sub ID. The old refresh token is still tied to the deleted user’s sub, so Cognito sees it as invalid (since that original user is gone).
  • The refresh token was issued for a different user instance: Even if you didn’t intentionally delete the user, there might have been a scenario where the user was removed and restored (e.g., via automated scripts or accidental deletion) with a new sub. The existing refresh token won’t recognize this new user instance.
  • Rare: Cognito cache or configuration glitches: In edge cases, Cognito’s internal cache might be out of sync, showing the user as existing but still checking against an old record. This is far less common, but worth ruling out.

How to Resolve It

Here’s what you can do to fix this:

  1. Decode the refresh token to check its sub claim: Use a JWT decoder (you can do this locally with libraries like jsonwebtoken in Node.js, or even a simple offline tool) to pull the sub value from the token. Then go to your Cognito user pool, find the existing user, and compare their sub ID. If they don’t match, the token belongs to a deleted user—your only fix is to have the user re-authenticate to get a new refresh token tied to the current user’s sub.
  2. Check user deletion history: Review your Cognito user pool’s audit logs to see if the user was ever deleted and recreated. If that’s the case, old tokens are permanently invalid for the new user.
  3. Verify token validity and revocation status: Double-check that the refresh token hasn’t expired (check your app client’s token expiration settings) and hasn’t been revoked manually in the user’s Cognito details. While this usually throws a different error, it’s worth eliminating as a possibility.

内容的提问来源于stack exchange,提问作者Shashwat Tripathi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 11:28:54