Step by Step guide to setup single sign-on into WordPress using AWS cognito with OpenId Connect protocol

If you want users to login to your WordPress site using their AWS cognito credentials, you can simply do it using our WP OAuth Client plugin. Once you configure the AWS cognito with WordPress plugin, you can allow users to SSO to your WordPress site using AWS cognito . Similarly, you can map your WordPress roles based on your AWS cognito attributes/groups. To know more about other features we provide in WP OAuth Client plugin, you can click here.

Step by Step guide to configure AWS Cognito as an OAuth/OpenId Connect Server

  • First of all, go to and sign up/login in your account to Configure AWS Cognito.
  • Login to Amazon Console
  • Search for Cognito in the AWS Services search bar as shown below.
  • Search for AWS Cognito
  • Click on Mange User Pools button to see the list of your user pools.
  • AWS Cognito User Pools
  • Click on Create a user pool to create a new user pool.
  • Create New AWS Cognito Pool
  • Add a Pool Name and click on the Review Defaults button to continue.
  • Name your AWS Cognito User Pool
  • Scroll down and click on the Add App Client option in front of App Clients.
  • AWS Cognito App Client
  • Click on Add an App Client. Enter an App Client Name and click on Create app client to create an App client.
  • Create App Client
  • Click on Return to Pool Details to come back to your configuration.
  • Configure AWS Cognito Pool
  • Click on Create Pool button to save your settings and create a user pool.
  • Save AWS Cognito Pool
  • In the navigation bar present on the left side, click on the App Client Settings option under the App Integration menu.
  • AWS Cognito App Details
  • Enter your Callback/Redirect URL which you will get from your miniOrange plugin present on your Client side under the CallBack URLs text-field. Select Authorization code grant checkbox under the Allowed OAuth Flows and also select openid and profile checkboxes under the Allowed OAuth Scopes option (Please refer to the image below). Click on the Save Changes button to save your configurations.
  • Configure AWS Cognito App Client
  • Click on Choose Domain Name option to set a domain name for your app.
  • AWS Cognito Domain Names
  • Enter your Domain Name under the Domain Prefix text-field and click on the Save Changes button to save your domain name.
  • Configure AWS Cognito Domain Name
  • Click on App Clients option under the General Settings menu in the left side navigation bar. Then, click on the Show Details button to see your App details like Client ID, Client secret etc.
  • AWS Cognito App Client Details
  • Copy the Client App ID and Client App Secret text field values and save them under your miniOrange plugin present on the client side under the Client Id and the Client Secret text fields respectively.
  • AWS Cognito App Client Configuration
  • You have successfully completed your AWS Cognito App OAuth Server side configurations.
  • You can download OAuth Client plugin using the following link.
    OAuth Single Sign On – SSO (OAuth client)

    AWS Cognito Endpoints and Scope:

    Client ID : from the step 9 above
    Client Secret : from the step 9 above
    Scope: openid
    Authorize Endpoint: https://<cognito-app-domain>/oauth2/authorize
    Access Token Endpoint: https://<cognito-app-domain>/oauth2/token
    Get User Info Endpoint: https://<cognito-app-domain>/oauth2/userInfo
    Custom redirect URL after logout:[optional] https://<cognito-app-domain>/logout?client_id=<Client-ID>&logout_uri=<Sign out URL configured in Cognito Portal>

Free Trial

If you are facing any difficulty please mail us on