<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00008MNg5ICATOkta Classic EngineSingle Sign-OnAnswered2022-11-14T11:55:40.000Z2022-11-14T09:03:58.000Z2022-11-14T11:55:40.000Z

OlegT.09904 (Customer) asked a question.

Bad id_token issuer error - AWS Cognito to OKTA IDP SSO

Hi,

I have set SSO OpenID Between Cognito and OKTA.

Our Webapp -> (OpenID) -> Cognito -> (OpenID) -> OKTA (idp with users)

 

When we initiate the flow from Webapp, it goes correctly to Okta thrugh Cognito, we are doing login in OKTA, and then returning back to Cognito, but in Cognito we are getting error "Bad id_token issuer". This error is returned to the webapp callback page instead of authorization code.

 

Same setup works fine in our AWS dev environment in another account and another dev OKTA account.

 

Probably Cognito fails to open the id_token that it gets from OKTA. Can you help to figure out what is wrong?


This question is closed.
Loading
Bad id_token issuer error - AWS Cognito to OKTA IDP SSO