Skip to main content

Powering machine-to-machine authorization using Amazon Cognito with nCino

Learn how banking technology company nCino unified identity services with zero disruption to tenants by using Amazon Cognito.

Benefits

framework for internal and external connectivity
1
disruption migration to a unified solution
0

Overview

As nCino sought to scale and evolve in the highly regulated financial sector, it needed to securely support external partner integrations while upholding stringent industry requirements. Drawing on its existing identity solutions on Amazon Web Services (AWS), the company built a resilient, standards-based machine-to-machine (M2M) authentication and authorization solution. To implement secure sign-in and access control for users, AI agents, and microservices in minutes, nCino used Amazon Cognito. Now, the company has a unified identity model across internal microservices and external partner integrations. This helps engineers focus on AI-driven capabilities and incorporate emerging technologies such as the Model Context Protocol.

 

Missing alt text value

About nCino

Founded in 2011 and headquartered in the United States, nCino provides intelligent banking solutions to over 2,700 customers worldwide and employs more than 1,700 people.

Opportunity | Securing external partner integrations for nCino

Financial institutions operate in a highly regulated environment with strict compliance, security, and resilience requirements. Increasingly asking for headless experiences, clients wanted to embed loan origination in their digital banking channels and internal applications.

nCino’s service-to-service authentication model served internal microservices well. But as client demand grew for external connectivity, nCino saw the opportunity to enhance its identity capabilities to meet industry-standard OAuth-based authentication protocols.

The company also needed identity resilience, which previously necessitated custom-built workarounds to meet disaster recovery objectives. Together, these efforts would support the scaling, security, and integration needs of emerging use cases.

Solution | Creating a unified identity solution using Amazon Cognito

When it identified M2M authorization capabilities within Amazon Cognito, nCino set out to build on its existing AWS identity solutions. “Amazon Cognito offered a single identity layer for internal microservices and external partners without introducing a new provider,” says Lauren Engelbert, foundational partnerships manager at nCino. “Choosing an AWS solution that fit naturally into our existing architecture was a significant selling point.”

The company uses Amazon API Gateway—a service for creating, publishing, maintaining, monitoring, and securing APIs—as the entry point to its microservices. To establish a consistent external-facing API solution for identity verification, nCino issues OAuth-based tokens for M2M authorization through Amazon Cognito. The company also enforces token validation at the Amazon API Gateway layer before requests reach backend services.

When building its authentication solution, nCino implemented an abstraction layer on top of Amazon Cognito to shield solution and engineering teams from backend identity complexity. The company then carried out a phased migration, using proxy services to maintain continuity for existing workflows. Within its multi-tenancy framework, nCino uses Amazon Cognito to isolate tenant identities. To help meet strict data residency and resilience requirements across its global customer base, the company aligns identity resources to each tenant’s geographic location.

Using Amazon Cognito, nCino runs one consistent, OAuth-based identity model across partners and internal services, which simplifies client conversations around security. The AWS team provided comprehensive technical expertise, helping nCino validate the solution architecture and compliance objectives before it committed engineering resources.

Through ongoing dialogue, nCino raised its resilience needs. Because Amazon Cognito supports data replication across multiple AWS Regions, the company is retiring its in-house tooling, which was built solely to provide this capability. “Collaborating with the AWS team, we’re solving identity challenges and building with confidence,” says Alex Arzaghi, director of platform engineering at nCino.

Outcome | Powering M2M identity at scale across nCino’s solution

The company completed the migration with zero disruption to tenants. Following the AWS Shared Responsibility Model, nCino’s multi-tenant environment now uses a unified, standards-based identity layer that spans internal and external connectivity, supporting a growing base of enterprise customers. With the abstraction layer on top of Amazon Cognito, the company has reduced the undifferentiated heavy lifting for engineering teams, helping them focus on developing new AI-driven and agentic workflows and adopting emerging standards such as the Model Context Protocol.

As part of its broader evolution toward agentic banking, nCino is also using Amazon Bedrock, a service for building generative AI applications and agents at production scale. To build, connect, and optimize agents for banking-specific workflows, nCino built its agentic operating system on Amazon Bedrock AgentCore—which integrates with other AWS services.

“Amazon Cognito started us on the right path from day one,” says Arzaghi. “As our use cases evolve, the same framework handles identity across our services. We operate as an agentic enterprise where services and agents are authenticated, authorized, and managed with the same rigor.”

Missing alt text value
Amazon Cognito started us on the right path from day one. As our use cases evolve, the same framework handles identity across our services.

Alex Arzaghi

Director of Platform Engineering, nCino

Did you find what you were looking for today?

Let us know so we can improve the quality of the content on our pages