NotAuthorizedException 🔐 Authentication

AWS Cognito: NotAuthorizedException: Incorrect username or password

Cognito rejected the sign-in — wrong credentials, a disabled user, an auth flow not enabled on the app client, or an expired refresh token.

Seen on: REST API

Meaning

Cognito returns NotAuthorizedException for several cases; the message differs: “Incorrect username or password”, “User is disabled”, “Refresh Token has expired”, or “Unable to verify secret hash for client” (secret hash issue).

Common causes

  • Wrong username/password
  • User disabled
  • ALLOW_USER_PASSWORD_AUTH / USER_SRP_AUTH not enabled on the app client
  • Refresh token expired/revoked

⚡ Quick fix

  1. Read the exact message
  2. Enable the needed auth flows on the app client
  3. Re-authenticate when refresh tokens expire

Detailed fix by platform

AWS CLI

  1. aws cognito-idp describe-user-pool-client --user-pool-id eu-west-1_abc --client-id $CLIENT --query 'UserPoolClient.ExplicitAuthFlows'

How to diagnose

  1. Message — Which variant?
  2. User — Enabled/confirmed?
  3. Client — Auth flows

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.