Connect to existing AWS resources
Amplify client libraries can be used independently without the Amplify backend workflow. If you've provisioned AWS resources with CDK, Terraform, CloudFormation, or the AWS Console, you can connect Amplify libraries directly to those resources.
This means you can adopt Amplify's client libraries for authentication, data, storage, and more — while keeping full control over your infrastructure.
When to use this approach
- You already have AWS resources provisioned with CDK, Terraform, or CloudFormation
- You want to use Amplify client libraries without adopting the Amplify backend (
ampx) workflow - You need to connect to shared infrastructure managed by a platform team
- You want programmatic control over configuration for testing or environment switching
How it works
There are two ways to configure Amplify client libraries with your own resources:
Option 1: Manual amplify_outputs.json
Create an amplify_outputs.json file with your resource configuration. See the full specification for all supported fields.
{ "version": "1", "auth": { "aws_region": "us-east-1", "user_pool_id": "us-east-1_abc123", "user_pool_client_id": "abcdef123456", "identity_pool_id": "us-east-1:11111111-2222-3333-4444-555555555555" }}Then generate the Dart configuration and configure Amplify:
npx ampx generate outputs --outputs-format dart --outputs-out-dir libimport 'amplify_outputs.dart';
await Amplify.addPlugin(AmplifyAuthCognito());await Amplify.configure(amplifyConfig);Option 2: Programmatic configuration with AmplifyOutputs
Build the configuration in code without any files:
import 'package:amplify_core/amplify_core.dart';import 'package:amplify_auth_cognito/amplify_auth_cognito.dart';
final config = AmplifyOutputs( auth: AuthOutputs( awsRegion: 'us-east-1', userPoolId: 'us-east-1_abc123', userPoolClientId: 'abcdef123456', ),);
await Amplify.addPlugin(AmplifyAuthCognito());await Amplify.configure(config);This approach is ideal for:
- Unit testing — Configure Amplify without bundling files
- Environment switching — Build different configurations for dev/staging/prod
- Dynamic configuration — Fetch configuration from a remote source at runtime
Configure Auth (Amazon Cognito)
Connect to an existing Cognito User Pool and Identity Pool.
final config = AmplifyOutputs( auth: AuthOutputs( awsRegion: 'us-east-1', userPoolId: 'us-east-1_abc123', userPoolClientId: 'abcdef123456', identityPoolId: 'us-east-1:11111111-2222-3333-4444-555555555555', passwordPolicy: PasswordPolicy( minLength: 8, requireNumbers: true, requireLowercase: true, requireUppercase: true, requireSymbols: false, ), oauth: OAuthOutputs( identityProviders: [IdentityProvider.google, IdentityProvider.apple], domain: 'myapp.auth.us-east-1.amazoncognito.com', scopes: ['openid', 'email', 'profile'], redirectSignInUri: ['myapp://callback'], redirectSignOutUri: ['myapp://signout'], responseType: 'code', ), standardRequiredAttributes: [CognitoStandardAttribute.email], usernameAttributes: [UsernameAttribute.email], userVerificationTypes: [VerificationType.email], unauthenticatedIdentitiesEnabled: true, mfaConfiguration: MfaEnforcement.optional, mfaMethods: [MfaMethod.sms, MfaMethod.totp], ),);
await Amplify.addPlugin(AmplifyAuthCognito());await Amplify.configure(config);Auth required fields
| Field | Required | Description |
|---|---|---|
awsRegion | Yes | AWS region (e.g. us-east-1) |
userPoolId | Yes | Cognito User Pool ID |
userPoolClientId | Yes | Cognito app client ID |
identityPoolId | No | Cognito Identity Pool ID (needed for guest access and IAM-based auth) |
passwordPolicy | No | Password requirements (min length, character types) |
oauth | No | OAuth/Hosted UI configuration (social sign-in) |
mfaConfiguration | No | MFA mode: NONE, OPTIONAL, or REQUIRED |
mfaMethods | No | MFA types: SMS, TOTP |
Configure Data (AWS AppSync)
Connect to an existing AppSync GraphQL API.
final config = AmplifyOutputs( data: DataOutputs( awsRegion: 'us-east-1', url: 'https://abc123.appsync-api.us-east-1.amazonaws.com/graphql', apiKey: 'da2-abcdefghijklmno', defaultAuthorizationType: AuthorizationType.apiKey, authorizationTypes: [AuthorizationType.apiKey, AuthorizationType.userPools], ),);
await Amplify.addPlugin(AmplifyAPI());await Amplify.configure(config);Data required fields
| Field | Required | Description |
|---|---|---|
awsRegion | Yes | AWS region |
url | Yes | AppSync GraphQL endpoint URL |
defaultAuthorizationType | Yes | Default auth mode: API_KEY, AMAZON_COGNITO_USER_POOLS, AWS_IAM, or OPENID_CONNECT |
authorizationTypes | Yes | All supported auth modes |
apiKey | No | Required if using API_KEY auth |
Configure Storage (Amazon S3)
Connect to an existing S3 bucket.
final config = AmplifyOutputs( auth: AuthOutputs( awsRegion: 'us-east-1', userPoolId: 'us-east-1_abc123', userPoolClientId: 'abcdef123456', identityPoolId: 'us-east-1:11111111-2222-3333-4444-555555555555', ), storage: StorageOutputs( awsRegion: 'us-east-1', bucketName: 'my-app-bucket', ),);
await Amplify.addPlugin(AmplifyAuthCognito());await Amplify.addPlugin(AmplifyStorageS3());await Amplify.configure(config);Multiple buckets
final config = AmplifyOutputs( storage: StorageOutputs( awsRegion: 'us-east-1', bucketName: 'primary-bucket', buckets: [ BucketOutputs(name: 'media', bucketName: 'my-media-bucket', awsRegion: 'us-east-1'), BucketOutputs(name: 'logs', bucketName: 'my-logs-bucket', awsRegion: 'us-west-2'), ], ),);Storage required fields
| Field | Required | Description |
|---|---|---|
awsRegion | Yes | AWS region |
bucketName | Yes | Default S3 bucket name |
buckets | No | Additional named buckets for multi-bucket setups |
Configure Analytics (Amazon Pinpoint)
Connect to an existing Pinpoint application.
final config = AmplifyOutputs( analytics: AnalyticsOutputs( amazonPinpoint: AmazonPinpointOutputs( awsRegion: 'us-east-1', appId: 'abc123def456', ), ),);
await Amplify.addPlugin(AmplifyAnalyticsPinpoint());await Amplify.configure(config);Configure Geo (Amazon Location Service)
Connect to existing Location Service resources.
Configure Notifications (Push)
Connect to an existing Pinpoint application for push notifications.
{ "version": "1", "notifications": { "aws_region": "us-east-1", "amazon_pinpoint_app_id": "abc123def456", "channels": ["APNS", "FCM", "IN_APP_MESSAGING"] }}Multi-category configuration
You can configure multiple services together. This example sets up Auth, Data, and Storage in a single configuration.
final config = AmplifyOutputs( auth: AuthOutputs( awsRegion: 'us-east-1', userPoolId: 'us-east-1_abc123', userPoolClientId: 'abcdef123456', identityPoolId: 'us-east-1:11111111-2222-3333-4444-555555555555', ), data: DataOutputs( awsRegion: 'us-east-1', url: 'https://abc123.appsync-api.us-east-1.amazonaws.com/graphql', defaultAuthorizationType: AuthorizationType.userPools, authorizationTypes: [AuthorizationType.userPools, AuthorizationType.iam], ), storage: StorageOutputs( awsRegion: 'us-east-1', bucketName: 'my-app-bucket', ),);
await Amplify.addPlugin(AmplifyAuthCognito());await Amplify.addPlugin(AmplifyAPI());await Amplify.addPlugin(AmplifyStorageS3());await Amplify.configure(config);Environment-specific configuration
Switch between dev, staging, and production without separate files:
final environment = const String.fromEnvironment('ENV', defaultValue: 'dev');
final AuthOutputs authConfig;switch (environment) { case 'prod': authConfig = AuthOutputs( awsRegion: 'us-east-1', userPoolId: 'us-east-1_prod789', userPoolClientId: 'prodClient789', ); case 'staging': authConfig = AuthOutputs( awsRegion: 'us-west-2', userPoolId: 'us-west-2_staging456', userPoolClientId: 'stagingClient456', ); default: authConfig = AuthOutputs( awsRegion: 'us-east-1', userPoolId: 'us-east-1_dev123', userPoolClientId: 'devClient123', );}
final config = AmplifyOutputs(auth: authConfig);await Amplify.configure(config);amplify_outputs.json schema reference
For the full schema of all supported configuration fields, see the amplify_outputs.json reference.