Approve a pending CLI login request (authenticated, audited). The approver's identity comes from the session — the body carries only the code, in either form.
Change the current user's password. Runs on the AUTHENTICATED pipeline and carries the Cognito access token (read from the credential store) in the body — Cognito's ChangePassword requires the access token, not the idToken bearer. Tokens are not rotated, so nothing is persisted here.
Complete a self-service password reset with the emailed code and a new password (auth-less base pipeline). On success the user can log in with the new password; no session is established here.
Deny a pending CLI login request (authenticated, audited).
Respond to a NEW_PASSWORD_REQUIRED challenge with a new password; on
success persists the resulting session to the credential store exactly
like login.
Start a self-service password reset (runs on the auth-less base pipeline — the user is logged out). The backend returns an anti-enumeration success regardless of whether the account exists.
Probe a temporary-password / challenge session WITHOUT authenticating.
Returns { requiresChallenge, session?, … }; persists nothing (there is
no token yet). On requiresChallenge: true, feed session into
forceChangePassword. This is the signup/temp-password entry point —
login cannot be used because the backend errors on a challenge.
Approval-page metadata for a CLI login request (authenticated).
userCode accepts either the display (WXYZ-2345) or stored
(WXYZ2345) form — the backend normalizes before lookup.
Interactive login; persists the session to the credential store.
Ends the backend session and clears stored credentials.
Identity of the current credential.
Persist a freshly-issued token set, deriving expiresAt from the
idToken. Public so the CLI browser-login flow can persist the polled
tokens AFTER creating the target profile (pollCliLogin itself never
persists).
One CLI browser-login token poll (auth-less base pipeline). Thin
delegate to AuthApi.pollCliLogin; persists NOTHING even on
approved — the CLI creates the target profile first, then calls
persistSession with the returned tokens.
Begin a CLI browser-login request (auth-less base pipeline). Thin
delegate to AuthApi.startCliLogin; persists nothing.
The
client.authnamespace: session management (login/logout) and identity inspection (me). Login runs on the auth-less base pipeline; the resulting session is persisted to the client's credential store so subsequent requests (and, on Node, the CLI) pick it up.