# OpenID error after authenticating against AWS Cognito

**URL:** <https://discuss.elastic.co/t/openid-error-after-authenticating-against-aws-cognito/206018>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [October 31, 2019, 10:11am UTC](https://discuss.elastic.co/t/openid-error-after-authenticating-against-aws-cognito/206018 "2019-10-31T10:11:41Z")\
**Posts on this page:** 1\
**Showing post:** 12

<div class="post-metadata">

**Author:** ![nahojkap](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nahojkap/32/56856_2.png) [@nahojkap](https://discuss.elastic.co/u/nahojkap)\
**Post date:** [November 13, 2019, 3:02pm UTC](https://discuss.elastic.co/t/openid-error-after-authenticating-against-aws-cognito/206018/12 "2019-11-13T15:02:23Z")

</div>

@ikakavas Resorted to debugging this locally and it seem AWS is returning claims with values of different types in token request vs user info:

`"email_verified": true`  
vs  
`"email_verified": "true"`

Parsing fails and as a result the authentication times out. Removing one of the claims before the merge happens fixes this problem and authentication is possible. Worth noting that there is nothing logged about this error, its simply times out.

Checking why AWS insists on sending the email\_verified claim even when I set the scope to openid only

---

_[View the full topic](https://discuss.elastic.co/t/openid-error-after-authenticating-against-aws-cognito/206018)._
