# PPL with AWS Cognito Groups

**URL:** <https://discuss.pomerium.com/t/ppl-with-aws-cognito-groups/57>\
**Category:** Support\
**Tags:** idp\
**Created:** [January 5, 2022, 7:51pm UTC](https://discuss.pomerium.com/t/ppl-with-aws-cognito-groups/57 "2022-01-05T19:51:15Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![alex](https://yyz1.discourse-cdn.com/flex031/user_avatar/discuss.pomerium.com/alex/32/9_2.png) [@alex](https://discuss.pomerium.com/u/alex)\
**Post date:** [January 5, 2022, 7:51pm UTC](https://discuss.pomerium.com/t/ppl-with-aws-cognito-groups/57/1 "2022-01-05T19:51:15Z")

</div>

> [@](#):
>
> [**View in #support on Slack**](https://slack.com/archives/CK92MUAES/p1641405068104700)
> 
> ![Noam_Ross](https://canada1.discourse-cdn.com/flex031/uploads/pomerium/original/1X/4b657c386b00483fb910f225e443b1790610a548.jpeg) **@Noam\_Ross:** Hello everyone! I’ve newly set up Pomerium for my organization as a secure layer in front of static site hosting, using AWS Cognito as our IDP. Great software. I’m trying to figure out the correct syntax for allowing access based on IDP claims (`cognito:groups`) under `routes:` . I think it is something like this, but it’s not quite right and the docs only show it under the deprecated top-level `policy:` block:
> 
> ```auto
> routes:
> - from: <https://nipah-bangladesh.secure.eha.io>
> to: <http://rclone>
> policy:
> - allow:
> or:
> - allowed_idp_claims:
> cognito:groups:
> - nipah-bangladesh
> 
> ```
> 
> ![Denis_Mishin](https://canada1.discourse-cdn.com/flex031/uploads/pomerium/original/1X/f994d4ba0807d7f7ff39a7ea42d696f7d611bd46.png) **@Denis\_Mishin:** 1. check that you have groups in the IDP claims, by visiting a special `/.pomerium` route once you’re authenticated - `<https://nipah-bangladesh.secure.eha.io/.pomerium>`  
> 2. there is a shortcut setting `allowed_groups` [https://www.pomerium.com/reference/#allowed-groups](https://www.pomerium.com/reference/#allowed-groups)
> 
> ![Noam_Ross](https://canada1.discourse-cdn.com/flex031/uploads/pomerium/original/1X/4b657c386b00483fb910f225e443b1790610a548.jpeg) **@Noam\_Ross:** `allowed_groups` doesn’t apply to to cognito groups ([https://github.com/pomerium/pomerium/issues/494#issuecomment-889981594](https://github.com/pomerium/pomerium/issues/494#issuecomment-889981594)), but yes, I have the `"cognito:groups"` in my IDP claims. Now trying this, but it’s not currently working (in that my user has that group but I’m getting a 403 error still).
> 
> ```auto
> routes:
> - from: <https://nipah-bangladesh.secure.eha.io>
> to: <http://rclone>
> policy:
> - allow:
> and:
> - "claim/cognito:groups":
> has: nipah-bangladesh
> 
> ```
> 
> ![Denis_Mishin](https://canada1.discourse-cdn.com/flex031/uploads/pomerium/original/1X/f994d4ba0807d7f7ff39a7ea42d696f7d611bd46.png) **@Denis\_Mishin:** I don’t have Cognito set up to check for myself, but could you try this instead ?
> 
> ```auto
> routes:
> - from: <https://nipah-bangladesh.secure.eha.io>
> to: <http://rclone>
> allowed_idp_claims:
> cognito:groups:
> - nipah-bangladesh    
> 
> ```
> 
> ![Caleb_Doxsey](https://canada1.discourse-cdn.com/flex031/uploads/pomerium/original/1X/2ae298c09a39e80b418afe69971e1bf8296942ad.jpeg) **@Caleb\_Doxsey:** `claim/cognito:groups` should be a string, not an object with `has`:
> 
> ```auto
> and:
> - "claim/cognito:groups": nipah-bangladesh
> 
> ```
> 
> [https://github.com/pomerium/pomerium/issues/2851#issuecomment-1002714076](https://github.com/pomerium/pomerium/issues/2851#issuecomment-1002714076)
> 
> ![Noam_Ross](https://canada1.discourse-cdn.com/flex031/uploads/pomerium/original/1X/4b657c386b00483fb910f225e443b1790610a548.jpeg) **@Noam\_Ross:** That did it, @Caleb\_Doxsey, thanks both!
