Avoid app-by-app coding
Use a proxy pattern when each application team cannot add Cognito SDKs or rewrite login flows.
Amazon Cognito for existing apps
Use Datawiza Access Proxy to put Amazon Cognito login and MFA in front of web applications that are not ready for direct Cognito integration or source-code changes.

Why it matters
Use a proxy pattern when each application team cannot add Cognito SDKs or rewrite login flows.
Extend Cognito-backed authentication to apps that were not built for modern identity protocols.
Challenge users before traffic reaches the app instead of relying on the app to enforce MFA.
Apply one deployment pattern across web apps, portals, and internal tools.
How it works
Place Datawiza Access Proxy before the application in the request path.
Use Cognito as the identity provider for login and MFA where it fits your AWS identity architecture.
Apply identity, group, app path, and rollout rules before allowing requests through.
Forward approved traffic to the existing application without requiring the app to integrate directly with Cognito.
Best fit
This pattern is useful when your identity strategy includes Amazon Cognito, but the application portfolio includes older web apps, custom portals, or on-prem systems that are hard to modify.
For the broader MFA strategy, see no-code MFA and Datawiza Access Proxy.
Good candidates include
Existing web apps that need Cognito login but cannot be rewritten quickly
Customer, partner, or internal portals running in AWS or hybrid environments
Legacy applications where MFA should happen before app access
Teams that want one proxy-based rollout pattern across several apps
Deployment
Run close to apps and identity services already operating in AWS.
Protect apps that span AWS, private cloud, and on-premises networks.
Start with one app, then repeat the same pattern for additional web properties.
Use proxy-level events to improve visibility into login and access decisions.
FAQ
Yes, Datawiza can sit in front of browser-based applications and enforce Cognito-backed login and MFA before traffic reaches the app.
No. The proxy pattern avoids app-by-app SDK work for many web applications because Datawiza handles access enforcement before the app.
Yes. Datawiza can support hybrid environments where the identity provider is Cognito but some applications run outside AWS.
No. It can also support partner portals, internal tools, admin apps, and other browser-based web applications.
Use Datawiza to put Cognito login and MFA in front of one web app without waiting for app code changes.
Sign up to secure your AI agents and critical enterprise apps