# OpenID error after authenticating against AWS Cognito

**URL:** <https://discuss.elastic.co/t/openid-error-after-authenticating-against-aws-cognito/206018>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [October 31, 2019, 10:11am UTC](https://discuss.elastic.co/t/openid-error-after-authenticating-against-aws-cognito/206018 "2019-10-31T10:11:41Z")\
**Posts on this page:** 1\
**Showing post:** 11

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [November 12, 2019, 12:24pm UTC](https://discuss.elastic.co/t/openid-error-after-authenticating-against-aws-cognito/206018/11 "2019-11-12T12:24:24Z")

</div>

Glad you got this figured out

> [@nickbabkin](#):
>
> Just FYI,  
> after bit of playing around I was able to fix this by changing principal claim from:
> 
> `claims.principal: sub`
> 
> to:
> 
> `claims.principal: preferred_username`

This would mean that the ID Token didn't contain a `sub` claim which is rather strange. The logs ( if you get them from your support engineer ) would contain a line that says

`claims.principal not found in {your ID Tokens claims here in json format}`

---

_[View the full topic](https://discuss.elastic.co/t/openid-error-after-authenticating-against-aws-cognito/206018)._
