AWS Cognito: NotAuthorizedException: Incorrect username or password
Cognito rejected the sign-in — wrong credentials, a disabled user, an auth flow not enabled on the app client, or an expired refresh token.
Seen on:
REST API
Meaning
Cognito returns NotAuthorizedException for several cases; the message differs: “Incorrect username or password”, “User is disabled”, “Refresh Token has expired”, or “Unable to verify secret hash for client” (secret hash issue).
Common causes
- Wrong username/password
- User disabled
- ALLOW_USER_PASSWORD_AUTH / USER_SRP_AUTH not enabled on the app client
- Refresh token expired/revoked
⚡ Quick fix
- Read the exact message
- Enable the needed auth flows on the app client
- Re-authenticate when refresh tokens expire
Detailed fix by platform
AWS CLI
aws cognito-idp describe-user-pool-client --user-pool-id eu-west-1_abc --client-id $CLIENT --query 'UserPoolClient.ExplicitAuthFlows'
How to diagnose
- Message — Which variant?
- User — Enabled/confirmed?
- Client — Auth flows
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
Most viewed in Authentication
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026