<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/amazon-cognito-now-supports-machine-to-machine-authorization-without-a-user-pool-domain-pqqefhkyp" -->

---
title: Amazon Cognito now supports machine-to-machine...
description: Amazon Cognito adds a new GetClientToken API operation that lets app clients obtain access tokens for machine-to-machine authorization using client ID and...
canonical: https://daily.dev/posts/amazon-cognito-now-supports-machine-to-machine-authorization-without-a-user-pool-domain-pqqefhkyp
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Amazon Cognito now supports machine-to-machine authorization without a user pool domain | daily.dev
og:description: Amazon Cognito adds a new GetClientToken API operation that lets app clients obtain access tokens for machine-to-machine authorization using client ID and...
og:url: https://daily.dev/posts/amazon-cognito-now-supports-machine-to-machine-authorization-without-a-user-pool-domain-pqqefhkyp
og:image: https://api.daily.dev/og/posts/pQQEFhkyp.png
og:image:alt: Amazon Cognito now supports machine-to-machine authorization without a user pool domain
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Amazon Cognito now supports machine-to-machine authorization without a user pool domain

**[AWS](https://daily.dev/sources/aws)** · 1 min read · 0 upvotes · 0 comments

## Summary

Amazon Cognito adds a new GetClientToken API operation that lets app clients obtain access tokens for machine-to-machine authorization using client ID and secret, without needing a configured user pool domain. It works natively through AWS SDK, CLI, or API, supports AWS WAF and VPC interface endpoints (PrivateLink), and is available in all regions where Cognito user pools exist. The existing domain-based OAuth 2.0 client-credentials flow still works alongside it. Standard Cognito M2M pricing applies.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://aws.amazon.com/about-aws/whats-new/2026/08/amazon-cognito-get-client-token>

## Questions this post answers

### How do I get machine-to-machine access tokens from Amazon Cognito without setting up a user pool domain?

Use the new GetClientToken API operation, which lets an app client authenticate with its client ID and secret to receive an access token scoped to custom resource server permissions, without a configured user pool domain. It works natively through the AWS SDK, CLI, or direct API calls, and supports AWS WAF and VPC interface endpoints via AWS PrivateLink. The existing domain-based OAuth 2.0 client-credentials flow still remains available as an alternative.

_Teams wiring up service-to-service auth can track Cognito API changes like this on daily.dev._

### Does Amazon Cognito's GetClientToken API replace the OAuth 2.0 client-credentials flow?

No, GetClientToken is an additional path rather than a replacement. The existing domain-based OAuth 2.0 client-credentials flow remains fully available, so applications already using a user pool domain for machine-to-machine authorization do not need to migrate.

_Comparing Cognito authorization options before choosing one is easier with updates tracked on daily.dev._

## Similar posts on daily.dev

- [Amazon Cognito removes Machine-to-Machine app client price dimension](https://daily.dev/posts/amazon-cognito-removes-machine-to-machine-app-client-price-dimension-lqqsekkos) · AWS · 0 upvotes · 0 comments
- [Amazon Cognito now available as a skill in the Agent Toolkit for AWS](https://daily.dev/posts/amazon-cognito-now-available-as-a-skill-in-the-agent-toolkit-for-aws-nk8cz9jql) · AWS · 0 upvotes · 0 comments
- [AWS Cognito Has the Credentials, Just Not the Front Door](https://daily.dev/posts/aws-cognito-has-the-credentials-just-not-the-front-door-fnurolgyy) · API Evangelist · 0 upvotes · 0 comments
- [Amazon Cognito enhances client secret management with secret rotation and custom secrets](https://daily.dev/posts/amazon-cognito-enhances-client-secret-management-with-secret-rotation-and-custom-secrets-2tujecxpb) · AWS · 0 upvotes · 0 comments
- [OAuth support for the AWS MCP Server](https://daily.dev/posts/oauth-support-for-the-aws-mcp-server-ywajj8q9m) · AWS · 0 upvotes · 0 comments

---

Tags: [#aws](https://daily.dev/tags/aws), [#architecture](https://daily.dev/tags/architecture), [#authentication](https://daily.dev/tags/authentication), [#oauth](https://daily.dev/tags/oauth)

[View this post on daily.dev](https://daily.dev/posts/amazon-cognito-now-supports-machine-to-machine-authorization-without-a-user-pool-domain-pqqefhkyp)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Amazon Cognito now supports machine-to-machine authorization without a user pool domain","url":"https://daily.dev/posts/amazon-cognito-now-supports-machine-to-machine-authorization-without-a-user-pool-domain-pqqefhkyp","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/amazon-cognito-now-supports-machine-to-machine-authorization-without-a-user-pool-domain-pqqefhkyp"},"datePublished":"2026-08-31T19:04:41.493Z","dateModified":"2026-08-31T19:37:07.747Z","description":"Amazon Cognito adds a new GetClientToken API operation that lets app clients obtain access tokens for machine-to-machine authorization using client ID and...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/2587ee7271b19b73b7c9d67f739e4290?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/2587ee7271b19b73b7c9d67f739e4290?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"AWS","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"AWS","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/aws","url":"https://daily.dev/sources/aws"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/amazon-cognito-now-supports-machine-to-machine-authorization-without-a-user-pool-domain-pqqefhkyp","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"aws,architecture,authentication,oauth","timeRequired":"PT1M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"AWS","item":"https://daily.dev/sources/aws"},{"@type":"ListItem","position":3,"name":"Amazon Cognito now supports machine-to-machine authorization without a user pool domain"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/amazon-cognito-now-supports-machine-to-machine-authorization-without-a-user-pool-domain-pqqefhkyp#faq","mainEntity":[{"@type":"Question","name":"How do I get machine-to-machine access tokens from Amazon Cognito without setting up a user pool domain?","acceptedAnswer":{"@type":"Answer","text":"Use the new GetClientToken API operation, which lets an app client authenticate with its client ID and secret to receive an access token scoped to custom resource server permissions, without a configured user pool domain. It works natively through the AWS SDK, CLI, or direct API calls, and supports AWS WAF and VPC interface endpoints via AWS PrivateLink. The existing domain-based OAuth 2.0 client-credentials flow still remains available as an alternative. Teams wiring up service-to-service auth can track Cognito API changes like this on daily.dev."}},{"@type":"Question","name":"Does Amazon Cognito's GetClientToken API replace the OAuth 2.0 client-credentials flow?","acceptedAnswer":{"@type":"Answer","text":"No, GetClientToken is an additional path rather than a replacement. The existing domain-based OAuth 2.0 client-credentials flow remains fully available, so applications already using a user pool domain for machine-to-machine authorization do not need to migrate. Comparing Cognito authorization options before choosing one is easier with updates tracked on daily.dev."}}]}
```

