What's the difference between Amazon Cognito user pools and identity pools?

Last updated: 2019-04-19

I'm starting to use Amazon Cognito, and I'm unsure whether I should use user pools or identity pools for my business applications. What's the difference?

Short Description

User pools are for authentication (identify verification). With a user pool, your app users can sign in through the user pool or federate through a third-party identity provider (IdP).

Identity pools are for authorization (access control). You can use identity pools to create unique identities for users and give them access other AWS services.

Resolution

User pool use cases

Use a user pool when you need to:

Identity pool use cases

Use an identity pool when you need to:

For more example use cases, see Common Amazon Cognito Scenarios.