$npx skillfedfor your agent

cognitojwt

Decode and verify Amazon Cognito JWT tokens

With conditionsPyPI CryptographyReleased Jun 2021548.7K downloads / moMITPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — cognitojwt-1.4.1-py3-none-any.whl
v1.4.1 · released 2021-06-07 · 1 runtime deps: python-jose

Yes, but with caution. The package is straightforward and has no known vulnerabilities, making it suitable for projects that need basic Cognito token verification. However, it is abandoned (last release June 2021, repository archived), so you should verify that it remains compatible with your Python version and current Cognito token format. For new projects or those requiring active maintenance, consider whether AWS SDK or a maintained alternative better fits your risk tolerance.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires AWS Cognito credentials (region, user pool ID, app client ID).
  • In private VPC without internet gateway, set AWS_COGNITO_JWKS_PATH environment variable to point to a local jwks.json file.
  • Low install friction with a single runtime dependency (python-jose).

License · maintenance · safety

MIT (permissive) — MIT license (permissive) means you can use, modify, and distribute this package freely in both open-source and commercial projects with minimal restrictions.

last release 2021-06-07 (1894 days) · last repo commit 2024-04-19 · 73 stars · archived

0 known vulnerabilities (OSV.dev, 2026-08-14) · 548,652 downloads/mo, #6,060 on PyPI

Verify before relying

pip install cognitojwt[sync]

import cognitojwt

verified_claims = cognitojwt.decode(
    id_token,
    REGION,
    USERPOOL_ID,
    app_client_id=APP_CLIENT_ID
)
  • Whether the package remains compatible with modern Python versions beyond 3.7 despite classifiers listing only 3.6 and 3.7.
  • Whether abandonment affects real-world reliability for Cognito token verification or if the core functionality remains stable.
  • Current status of AWS Cognito JWT format compatibility—whether AWS has changed token structure since the last release.
Same gist for agents: .md · .json

What it is and what it does

cognitojwt is a lightweight library for validating Amazon Cognito ID tokens by decoding and verifying JWT signatures. It wraps python-jose to handle the cryptographic operations and fetches AWS public key sets (JWKS) to validate token signatures. The library supports both synchronous (using requests) and asynchronous (using aiohttp) modes, letting you choose based on your application architecture.

The package is designed for applications that need to verify Cognito tokens locally without making additional AWS API calls. It handles signature validation, token expiration checks (with an optional test mode to disable expiration), and supports single or multiple app client IDs. However, the repository is archived and no longer actively maintained, so it may not track changes to AWS Cognito's token format or security practices.

Use it for

  • Verify Cognito ID tokens in a Flask or FastAPI application protecting API endpoints.
  • Validate Cognito tokens asynchronously in event-driven or async Python applications.
  • Decode and extract claims from Cognito tokens for authorization decisions in microservices.
  • Test Cognito authentication flows locally by disabling token expiration checks.
  • Support applications deployed in private VPCs by loading JWKS from a local file instead of fetching from AWS.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, but with caution.

The package is straightforward and has no known vulnerabilities, making it suitable for projects that need basic Cognito token verification. However, it is abandoned (last release June 2021, repository archived), so you should verify that it remains compatible with your Python version and current Cognito token format. For new projects or those requiring active maintenance, consider whether AWS SDK or a maintained alternative better fits your risk tolerance.

Install

cognitojwt on PyPI

Before you install

Low install friction with a single runtime dependency (python-jose). However, the repository is archived and marked abandoned as of the fact sheet date, with the latest release from 2021-06-07 and no commits since 2024-04-19. Active maintenance is not expected.

Requires AWS Cognito credentials (region, user pool ID, app client ID). In private VPC without internet gateway, set AWS_COGNITO_JWKS_PATH environment variable to point to a local jwks.json file.

License in practice

MIT license (permissive) means you can use, modify, and distribute this package freely in both open-source and commercial projects with minimal restrictions.

Quickstart

pip install cognitojwt[sync]

import cognitojwt

verified_claims = cognitojwt.decode(
    id_token,
    REGION,
    USERPOOL_ID,
    app_client_id=APP_CLIENT_ID
)

Verify before relying

  • Whether the package remains compatible with modern Python versions beyond 3.7 despite classifiers listing only 3.6 and 3.7.
  • Whether abandonment affects real-world reliability for Cognito token verification or if the core functionality remains stable.
  • Current status of AWS Cognito JWT format compatibility—whether AWS has changed token structure since the last release.

Package facts

LicenseMIT permissive
Python supportNot specified
Install frictionLow. Pure-Python wheel
Runtime dependencies
1 package
python-jose
MaintenanceAbandoned 1,894 days since the last release
Last repo commit repository archived
First released
Downloads548,652 / month, #6,060 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 4 - BetaIntended Audience :: DevelopersLicense :: OSI Approved :: MIT LicenseOperating System :: OS IndependentProgramming Language :: Python :: 3.6Programming Language :: Python :: 3.7

Evidence: cognitojwt-1.4.1-py3-none-any.whl

Tags

Capabilities
cognito jwt decode verifyaws cognito token validationamazon cognito id tokenjwt verification cognitocognito async jwtcognito sync decodeaws token authentication
Topics
aws-cognitojwt-validationauthentication
PyPI keywords
AmazonCognitoJWT

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “cognito jwt decode verify”

  • cognitojwtDecodes and verifies Amazon Cognito JWT tokens in both synchronous…
  • fastapi-cloudauthIntegrates FastAPI applications with cloud authentication services…
  • Flask-CognitoFlask-Cognito integrates AWS Cognito JWT authentication into Flask…

Give your agent the search over MCP, or paste the wish link into any chat.

More Cryptography packages

certifi Worth it
PyPI · Cryptography · released Jul 2026

Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.

MPL-2.0pure Python · 3.7+
1.9Bdownloads / mo
cryptography Worth it
PyPI · Cryptography · released Jul 2026

cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.

Apache-2.0 OR BSD-3-Clausecompiled wheel
1.5Bdownloads / mo
rsa Skip
PyPI · Cryptography · released Apr 2025

Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.

Apache-2.0pure Pythonabandoned
299.6Mdownloads / mo
pyOpenSSL With conditions
PyPI · Python Modules · released Aug 2026

pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.

Apache-2.0pure Python · 3.9+
294.2Mdownloads / mo
azure-identity Worth it
PyPI · Cryptography · released Mar 2026

Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.

license unclearpure Python · 3.9+
247.2Mdownloads / mo
PyNaCl Worth it
PyPI · Cryptography · released Jan 2026

PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.

Apache-2.0compiled wheel · 3.8+
246.6Mdownloads / mo

See also atlassian-jwt-auth · fastapi-cognito · Flask-Cognito · pycognito · warrant · fastapi-cloudauth · pyjwt-key-fetcher · zi-api-auth-client · vercel-oidc · okta-jwt-verifier