Amplify has re-imagined the way frontend developers build fullstack applications. Develop and deploy without the hassle.

Page updated Jul 12, 2024

Grant access to auth resources

Amplify Auth can be defined with an access property, which allows other resources to interact with auth by specifying actions.

amplify/auth/resource.ts
import { defineAuth } from "@aws-amplify/backend"
import { addUserToGroup } from "../functions/add-user-to-group/resource"
/**
* Define and configure your auth resource
* @see https://docs.amplify.aws/gen2/build-a-backend/auth
*/
export const auth = defineAuth({
loginWith: {
email: true,
},
access: (allow) => [
allow.resource(addUserToGroup).to(["addUserToGroup"])
],
})

When you grant a function access to another resource in your Amplify backend it will configure environment variables for that function to make SDK calls to the AWS services it has access to. Those environment variables are typed and available as part of the env object.

List of actions

Action NameDescriptionCognito IAM Actions
manageUsersGrants CRUD access to users in the UserPool
  • cognito-idp:AdminConfirmSignUp
  • cognito-idp:AdminCreateUser
  • cognito-idp:AdminDeleteUser
  • cognito-idp:AdminDeleteUserAttributes
  • cognito-idp:AdminDisableUser
  • cognito-idp:AdminEnableUser
  • cognito-idp:AdminGetUser
  • cognito-idp:AdminListGroupsForUser
  • cognito-idp:AdminRespondToAuthChallenge
  • cognito-idp:AdminSetUserMFAPreference
  • cognito-idp:AdminSetUserSettings
  • cognito-idp:AdminUpdateUserAttributes
  • cognito-idp:AdminUserGlobalSignOut
manageGroupMembershipGrants permission to add and remove users from groups
  • cognito-idp:AdminAddUserToGroup
  • cognito-idp:AdminRemoveUserFromGroup
manageGroupsGrants CRUD access to groups in the UserPool
  • cognito-idp:GetGroup
  • cognito-idp:ListGroups
  • cognito-idp:CreateGroup
  • cognito-idp:DeleteGroup
  • cognito-idp:UpdateGroup
manageUserDevicesManages devices registered to users
  • cognito-idp:AdminForgetDevice
  • cognito-idp:AdminGetDevice
  • cognito-idp:AdminListDevices
  • cognito-idp:AdminUpdateDeviceStatus
managePasswordRecoveryGrants permission to reset user passwords
  • cognito-idp:AdminResetUserPassword
  • cognito-idp:AdminSetUserPassword
addUserToGroupGrants permission to add any user to any group.
  • cognito-idp:AdminAddUserToGroup
createUserGrants permission to create new users and send welcome messages via email or SMS.
  • cognito-idp:AdminCreateUser
deleteUserGrants permission to delete any user
  • cognito-idp:AdminDeleteUser
deleteUserAttributesGrants permission to delete attributes from any user
  • cognito-idp:AdminDeleteUserAttributes
disableUserGrants permission to deactivate any user
  • cognito-idp:AdminDisableUser
enableUserGrants permission to activate any user
  • cognito-idp:AdminEnableUser
forgetDeviceGrants permission to deregister any user's devices
  • cognito-idp:AdminForgetDevice
getDeviceGrants permission to get information about any user's devices
  • cognito-idp:AdminGetDevice
getUserGrants permission to look up any user by user name
  • cognito-idp:AdminGetUser
listUsersGrants permission to list users and their basic details in the UserPool
  • cognito-idp:ListUsers
listDevicesGrants permission to list any user's remembered devices
  • cognito-idp:AdminListDevices
listGroupsForUserGrants permission to list the groups that any user belongs to
  • cognito-idp:AdminListGroupsForUser
listUsersInGroupGrants permission to list users in the specified group
  • cognito-idp:ListUsersInGroup
removeUserFromGroupGrants permission to remove any user from any group
  • cognito-idp:AdminRemoveUserFromGroup
resetUserPasswordGrants permission to reset any user's password
  • cognito-idp:AdminResetUserPassword
setUserMfaPreferenceGrants permission to set any user's preferred MFA method
  • cognito-idp:AdminSetUserMFAPreference
setUserPasswordGrants permission to set any user's password
  • cognito-idp:AdminSetUserPassword
setUserSettingsGrants permission to set user settings for any user
  • cognito-idp:AdminSetUserSettings
updateDeviceStatusGrants permission to update the status of any user's remembered devices
  • cognito-idp:AdminUpdateDeviceStatus
updateUserAttributesGrants permission to updates any user's standard or custom attributes
  • cognito-idp:AdminUpdateUserAttributes