Datawiza

Amazon Cognito for existing apps

Extend Amazon Cognito SSO and MFA to Existing Web Apps

Use Datawiza Access Proxy to put Amazon Cognito login and MFA in front of web applications that are not ready for direct Cognito integration or source-code changes.

Explore No-Code MFA
Extending Amazon Cognito SSO login and MFA video

Why it matters

Cognito is powerful, but many existing apps cannot integrate directly

Avoid app-by-app coding

Use a proxy pattern when each application team cannot add Cognito SDKs or rewrite login flows.

Protect legacy and on-prem apps

Extend Cognito-backed authentication to apps that were not built for modern identity protocols.

Add MFA before access

Challenge users before traffic reaches the app instead of relying on the app to enforce MFA.

Standardize rollout

Apply one deployment pattern across web apps, portals, and internal tools.

How it works

Use Datawiza as the access layer in front of the app

Route app traffic through Datawiza

Place Datawiza Access Proxy before the application in the request path.

Connect Amazon Cognito

Use Cognito as the identity provider for login and MFA where it fits your AWS identity architecture.

Evaluate access policy

Apply identity, group, app path, and rollout rules before allowing requests through.

Deliver approved requests

Forward approved traffic to the existing application without requiring the app to integrate directly with Cognito.

Best fit

Where Cognito plus Datawiza fits

This pattern is useful when your identity strategy includes Amazon Cognito, but the application portfolio includes older web apps, custom portals, or on-prem systems that are hard to modify.

For the broader MFA strategy, see no-code MFA and Datawiza Access Proxy.

Good candidates include

Existing web apps that need Cognito login but cannot be rewritten quickly

Customer, partner, or internal portals running in AWS or hybrid environments

Legacy applications where MFA should happen before app access

Teams that want one proxy-based rollout pattern across several apps

Deployment

Fit the deployment to your AWS and hybrid environment

AWS-centered deployment

Run close to apps and identity services already operating in AWS.

Hybrid coverage

Protect apps that span AWS, private cloud, and on-premises networks.

Phased adoption

Start with one app, then repeat the same pattern for additional web properties.

Central visibility

Use proxy-level events to improve visibility into login and access decisions.

FAQ

Amazon Cognito SSO and MFA FAQ

Can Cognito protect apps that do not integrate with Cognito directly?

Yes, Datawiza can sit in front of browser-based applications and enforce Cognito-backed login and MFA before traffic reaches the app.

Do we need to install SDKs in every application?

No. The proxy pattern avoids app-by-app SDK work for many web applications because Datawiza handles access enforcement before the app.

Can this work outside AWS?

Yes. Datawiza can support hybrid environments where the identity provider is Cognito but some applications run outside AWS.

Is this only for customer-facing apps?

No. It can also support partner portals, internal tools, admin apps, and other browser-based web applications.

Test Cognito-backed MFA on one existing app

Use Datawiza to put Cognito login and MFA in front of one web app without waiting for app code changes.

Datawiza is Easy to Get Started

Sign up to secure your AI agents and critical enterprise apps

Try Datawiza