You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何查找给定Cognito身份所属的用户池用户?控制台及编程方式可行吗?

如何从Cognito Identity Pool身份关联到对应的User Pool用户

确实,Cognito Identity Pool里的身份(格式如<region>:<guid>)在控制台点击后只能看到基础信息,没法直接跳转到对应的User Pool用户。不过不管是控制台还是编程方式,都有办法间接完成这个关联查询,我给你详细说说:

一、AWS控制台方式

控制台没有直接的一键跳转,但可以通过以下步骤手动关联:

  • 打开目标Identity Pool的身份详情页,找到Linked logins区域,复制其中的用户池ID(就是cognito-idp.<region>.amazonaws.com/后面的那串字符)。
  • 进入对应的Cognito User Pool控制台,切换到Users and groups页面。
  • 回到Identity Pool的身份详情页,向下滚动到Attributes区域,这里会显示同步过来的User Pool用户属性(比如cognito:sub、email、username等,具体取决于你在User Pool里配置的同步规则)。
  • 复制其中一个唯一标识(比如cognito:sub的值),回到User Pool的用户列表,用搜索框搜索这个值,就能找到对应的用户了。

注意:如果Attributes区域没显示你需要的属性,可能是因为Identity Pool和User Pool的属性同步规则没配置好,需要检查User Pool的App Client里的"Attribute read and write permissions",以及Identity Pool的"Authentication providers"里的属性映射设置。

二、编程/CLI方式

如果需要批量或者自动化查询,用CLI或者SDK会更高效:

使用AWS CLI的步骤:

  1. 首先查询Identity Pool身份的详细信息,拿到关联的用户池ID和用户属性:
aws cognito-identity describe-identity --identity-id <你的Identity ID,比如us-east-1:xxxxxx-xxxx-xxxx-xxxx-xxxxxx>

这个命令的输出里,Logins字段会显示关联的User Pool地址,Attributes字段会包含来自User Pool的用户属性(比如cognito:sub、username)。

  1. 拿到cognito:sub或者username的值后,查询对应的User Pool用户:
# 用sub查询
aws cognito-idp admin-get-user --user-pool-id <你的User Pool ID> --username <cognito:sub的值>

# 或者用username查询(如果username是唯一的)
aws cognito-idp admin-get-user --user-pool-id <你的User Pool ID> --username <username的值>

使用SDK的示例(以Python为例):

import boto3

# 初始化客户端
cognito_identity_client = boto3.client('cognito-identity')
cognito_idp_client = boto3.client('cognito-idp')

# 1. 获取Identity详情
identity_id = 'us-east-1:xxxxxx-xxxx-xxxx-xxxx-xxxxxx'
identity_response = cognito_identity_client.describe_identity(IdentityId=identity_id)

# 提取User Pool ID和用户sub
user_pool_login = next(iter(identity_response['Logins'].keys()))
user_pool_id = user_pool_login.split('/')[-1]
user_sub = next(attr['Value'] for attr in identity_response['Attributes'] if attr['Name'] == 'cognito:sub')

# 2. 查询User Pool用户
user_response = cognito_idp_client.admin_get_user(
    UserPoolId=user_pool_id,
    Username=user_sub
)

print("对应的User Pool用户信息:", user_response)

注意:执行这些操作需要对应的IAM权限,比如cognito-identity:DescribeIdentity和cognito-idp:AdminGetUser权限。

内容的提问来源于stack exchange,提问作者mipnw

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.22 10:10:29