This guide explains the get-dotenv cognito plugin exported by this package:
cognitoPlugin() → mounts under aws and provides:
aws cognito pullaws cognito purgeIf you want the programmatic API instead, see the AwsCognitoTools guide.
npm i @karmaniverous/aws-cognito-tools
You can either:
aws-cognito-tools), orcognitoPlugin() inside your own get-dotenv host.The shipped CLI is a get-dotenv CLI host composed with aws + cognito:
aws-cognito-tools --env dev aws cognito pull --client-name web-app
aws-cognito-tools --env dev aws cognito purge --force
Notes:
--env is a get-dotenv root option and must appear before aws ....--pool-id and --client-name at action time against { ...process.env, ...ctx.dotenv } (ctx.dotenv wins).Mount the plugin under aws:
import { createCli } from '@karmaniverous/get-dotenv/cli';
import { awsPlugin } from '@karmaniverous/get-dotenv/plugins';
import { cognitoPlugin } from '@karmaniverous/aws-cognito-tools';
await createCli({
alias: 'smoz',
compose: (program) => program.use(awsPlugin().use(cognitoPlugin())),
})();
Region sourcing:
aws plugin's published ctx state (ctx.plugins.aws.region) when available.aws plugin may export them into process.env depending on its configuration).aws cognito pullPull resolves a User Pool and Client, then writes configured env vars to local dotenv files using JSONPath mappings.
Configure mappings in your get-dotenv config under plugins['aws/cognito']:
{
"pull": {
"mappings": {
"env": {
"public": {
"COGNITO_USER_POOL_ID": "$.userPool.Id",
"COGNITO_CLIENT_ID": "$.userPoolClient.ClientId",
"COGNITO_REGION": "$.region"
},
"private": {
"COGNITO_CLIENT_SECRET": "$.userPoolClient.ClientSecret"
}
}
}
}
}
The source object resolved against is:
{
userPool: DescribeUserPoolResponse.UserPool,
userPoolClient: DescribeUserPoolClientResponse.UserPoolClient,
region: string
}
| Option | Default | Description |
|---|---|---|
--pool-id |
$COGNITO_USER_POOL_ID |
User Pool ID (supports $VAR expansion) |
--client-name |
$COGNITO_USER_POOL_CLIENT_NAME |
Client name to find and describe |
--template-extension |
template |
Dotenv template extension for missing files |
--include |
none | Space-delimited keys to include (mutually exclusive with --exclude) |
--exclude |
none | Space-delimited keys to exclude (mutually exclusive with --include) |
--client-name (paginated search)scope → privacy → envVar → jsonPath, resolve the JSONPath--include/--exclude filteringeditDotenvFile with get-dotenv precedenceaws cognito purgePurge deletes all users from a Cognito User Pool. This is a destructive operation.
| Option | Default | Description |
|---|---|---|
--pool-id |
$COGNITO_USER_POOL_ID |
User Pool ID (supports $VAR expansion) |
--force |
false |
Required to confirm deletion |
Without --force, the command throws an error and does not proceed.
Full config schema (all optional):
{
"userPoolId": "$COGNITO_USER_POOL_ID",
"clientName": "$COGNITO_USER_POOL_CLIENT_NAME",
"templateExtension": "template",
"pull": {
"mappings": { ... },
"include": ["KEY1", "KEY2"],
"exclude": ["SECRET_KEY"]
}
}
CLI flags always override config values. Config values override defaults.