# AWS Cognito integration with Kibana

**URL:** <https://discuss.elastic.co/t/aws-cognito-integration-with-kibana/268604>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [March 28, 2021, 8:14pm UTC](https://discuss.elastic.co/t/aws-cognito-integration-with-kibana/268604 "2021-03-28T20:14:07Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![diwakar\_singh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/diwakar_singh/32/86182_2.png) [@diwakar\_singh](https://discuss.elastic.co/u/diwakar_singh)\
**Post date:** [March 28, 2021, 8:14pm UTC](https://discuss.elastic.co/t/aws-cognito-integration-with-kibana/268604/1 "2021-03-28T20:14:07Z")

</div>

Hi,

I'm using AWS Cognito as SSO authentication service for Kibana and my other web application. Everything seems to be working fine but there is one issue. After log in through Cognito, Kibana remains logged in as long as browser is open. But if user closes the browser and then comes back to access kibana, they can do so only till 1 hour after first login. After 1 hour, Kibana redirects the user to Cognito login page. However user is able to access my other web application even after 1 hour of first login. I'm not sure what exactly is happening here. In Kibana docs, it says that access token is valid for 20 minutes and refresh token for 24 hours and Kibana will only try to redirect to auth page after both tokens have expired. But here just after 1 hour user is being redirected.

Elasticsearch and Kibana Version: 7.10.2

Configuration in elasticsearch.yml:

```auto
    xpack.security.enabled : true
    xpack.security.authc.token.enabled: true

    oidc.cognito-oidc:
        order: 2
        rp.client_id: "<COGNITO_APP_CLIENT_ID>"
        rp.response_type: code
        rp.redirect_uri: "http://localhost:5601/api/security/oidc/callback"
        op.issuer: "https://cognito-idp.us-east-1.amazonaws.com/<COGNITO_USER_POOL_ID>"
        op.authorization_endpoint: "<AUTH_DOMAIN>/oauth2/authorize"
        op.token_endpoint: "<AUTH_DOMAIN>/oauth2/token"
        op.jwkset_path: "https://cognito-idp.us-east-1.amazonaws.com/<COGNITO_USER_POOL_ID>/.well-known/jwks.json"
        op.endsession_endpoint: "<AUTH_DOMAIN>/logout?client_id=<COGNITO_APP_CLIENT_ID>&logout_uri=http://localhost:5601/security/logged_out"
        rp.requested_scopes: [profile, email, openid]
        claims.principal: email
        claims.groups: cognito:groups

```

Configuration in kibana.yml:

```auto
    xpack.security.authc.providers:
        oidc.oidc1:
            order: 0
            realm: cognito-oidc
            description: "Log in with Cognito"
        basic.basic1:
            order: 1
    xpack.security.authc.selector.enabled: false
    server.xsrf.whitelist: [/api/security/oidc/callback]

```

In Cognito user pool, access token validity is set to 1 day.

Any help would be really appreciated.

Thank you!

---

<div class="post-metadata">

**Author:** ![azasypkin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/azasypkin/32/42216_2.png) [@azasypkin](https://discuss.elastic.co/u/azasypkin)\
**Post date:** [March 29, 2021, 8:53am UTC](https://discuss.elastic.co/t/aws-cognito-integration-with-kibana/268604/2 "2021-03-29T08:53:19Z")

</div>

Hey @diwakar_singh ,

Unfortunately, the fact that sessions stay active until the browser is closed is a known limitation. Please upvote the following issue if it's something you'd like us to improve in the future:

> <https://github.com/elastic/kibana/issues/36573>
>
> With xpack.security.sessionTimeout, you can extend the session timeout but it will always log out if the tab or browser window is...

Best,  
Oleg

---

<div class="post-metadata">

**Author:** ![diwakar\_singh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/diwakar_singh/32/86182_2.png) [@diwakar\_singh](https://discuss.elastic.co/u/diwakar_singh)\
**Post date:** [March 29, 2021, 12:54pm UTC](https://discuss.elastic.co/t/aws-cognito-integration-with-kibana/268604/3 "2021-03-29T12:54:38Z")

</div>

Alright, thanks for the reply @azasypkin . Hope this is implemented soon.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 26, 2021, 12:55pm UTC](https://discuss.elastic.co/t/aws-cognito-integration-with-kibana/268604/4 "2021-04-26T12:55:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
