Last updated: September 2026
Amazon Cognito is often still the right fit, but whether it stays that way depends on a few things you can check in an afternoon, chiefly what your bill looks like at several times today’s monthly active users, and whether your customers are starting to ask for things Cognito does not do cleanly, most often single sign-on with their own identity provider. Cognito prices by monthly active user (MAU), and AWS charges separately for users who sign in through a customer’s SAML or OpenID Connect identity provider, with a free tier of only 50 of those users across your account. For a B2B product that is moving upmarket, that federated line is the one that tends to grow fastest.
This post is for the CTO, VP of Engineering or founder whose product runs on Cognito today and who has a vague feeling it might not be the long-term answer. It is not a product comparison. It explains how Cognito pricing works today, why Cognito was probably the right call, what changes as your users and customer list grow, and the short list of checks to run before your next renewal, budget cycle or roadmap commitment. If you decide to look further, our developer guide to Cognito alternatives is the next step.
How does AWS Cognito pricing work?
Cognito’s user pool pricing is based on monthly active users. AWS’s Cognito FAQ counts a user as active in a calendar month when your app generates an identity operation for them, which includes sign-ins and token refreshes but also administrative operations such as creating, updating or looking up the user. According to AWS’s Amazon Cognito pricing page, retrieved in September 2026:
| What you pay for | How it is priced |
|---|---|
| Users signing in directly or with a social provider on Essentials (the default plan) | Free up to 10,000 MAUs per month per account or AWS organization, then $0.015 per MAU |
| Users signing in directly on Lite | Free up to 10,000 MAUs, then a lower per-MAU rate that falls in volume bands |
| Users signing in directly on Plus | $0.020 per MAU, with no free tier |
| Users signing in through SAML 2.0 or OIDC federation | Free up to 50 MAUs, then $0.015 per MAU, on every plan |
| Machine-to-machine token requests | Priced separately, by the number of successful token requests (AWS removed the separate per-app-client charge in November 2025) |
There is an important exception for older accounts. AWS’s announcement says accounts with user pools created on or before 22 November 2024 keep a free tier of 50,000 MAUs on the Lite plan, and AWS’s price match for those accounts moving to Essentials ran only until 30 November 2025. If your product has been on Cognito since before that date, your free tier may be five times larger than a new account’s, and any new pool you create on Essentials is now billed at the Essentials rate.
AWS changes these rates from time to time, so treat the table as the shape of the model and confirm the current figures on the pricing page when you build your own forecast.
Why was Cognito probably the right call to start?
Cognito comes with an AWS account, needs no separate vendor contract, and has a free tier that covers most early products. Since November 2024 AWS has offered three user pool feature plans, Lite, Essentials and Plus (“Announcing new feature tiers: Essentials and Plus for Amazon Cognito”, AWS What’s New, 22 November 2024), and Essentials became the default for new user pools. For a new account, the free tier covers the first 10,000 MAUs of direct and social sign-ins each month.
For a team whose whole stack already lives in AWS, that is a sensible trade. There is one fewer vendor to assess, billing arrives on the same invoice as everything else, and the integration with API Gateway, Application Load Balancer and IAM roles works out of the box. Before a product has real identity requirements, spending engineering time on an identity platform decision would usually be a distraction.
What changes as your user base and customer list grow?
Two things change, usually at different speeds. The bill grows with login activity, and the feature requests change as larger customers arrive with their own identity requirements. The second is often noticed first, because a blocked deal gets attention straight away while a rising line on an invoice does not.
Why do federated SSO users matter so much?
The federated line is where B2B products feel the pricing first. When you sign an enterprise customer and connect their Okta or Microsoft Entra ID tenant, every one of their employees who signs in that month counts as a federated MAU rather than a regular one, and only the first 50 across your account are free.
As a worked example using the published rate, your first enterprise customer with 5,000 employees who all sign in during a month adds about 4,950 billable federated MAUs, or roughly $74 that month. Ten customers of that size add around 50,000 federated MAUs, or roughly $750 a month, regardless of what those customers pay you. The numbers are not large on their own, but they grow with seat count rather than with contract value, which is the part worth modeling.
This is the same per-user pattern that runs through most hosted identity pricing. It is not a problem in itself, but it means your identity cost is tied to how many people log in, while your revenue from a large customer is tied to what you negotiated. Our vendor risk brief for CTOs calls this pricing model risk, and it is worth putting a number on it before a renewal forces the question.
Where do the gaps tend to show up first?
The first gap to surface is often not the bill but one of these requests from a larger prospect or customer:
- SSO with the customer’s own identity provider, set up per customer. Cognito supports SAML and OIDC federation, but deciding how tenants map to user pools, app clients and identity providers is design work, and AWS’s own multi-tenant guidance describes trade-offs between a shared user pool and a pool per tenant.
- Security evidence for procurement. On the Plus plan AWS lists exporting user authentication event logs, along with adaptive authentication and compromised credential detection. If a security review asks for customer-visible sign-in logs, check which plan you would need and what it costs at your volume. Our post on why having SSO doesn’t mean you’ll pass procurement covers what those reviews ask for beyond SSO.
- A sign-in flow more customized than the hosted pages allow. Step-up authentication for sensitive actions, custom consent screens, or organization-specific login rules can mean Lambda triggers and custom UI work.
- Provisioning and deprovisioning. Enterprise customers often want their identity provider to create and remove accounts automatically through SCIM, and reviewers ask how you handle leavers.
None of these is impossible on Cognito. The question is how much engineering time each one takes to build and maintain, and whether that time is going into your product or into working around your identity layer.
Which signal matters more, the invoice or a stalled deal?
A single enterprise deal held up by a missing identity feature is usually a stronger signal than the bill, because it puts a dollar figure on the gap. If a prospect worth a meaningful share of your annual revenue is waiting on SSO configuration, SCIM or audit log access, the cost of the workaround is that deal, plus the next one that asks for the same thing.
The invoice is a slower signal but an easier one to forecast. If your federated MAUs are growing faster than your overall user count, that tells you your customer mix is moving towards enterprise accounts, which is also when the feature requests above become more frequent. The two signals tend to arrive together, so it helps to look at both at the same time.
What should you check before your next renewal or roadmap review?
Three checks cover most of the decision, and none of them requires committing to a change.
- Model the bill at three and ten times today. Split your current MAUs into direct, social and federated users, apply the current rates from AWS’s pricing page, and project each group forward using your sales plan rather than a flat growth rate. Pay particular attention to federated users, because each new enterprise customer adds its whole workforce to that line.
- List the identity requests you have already received. Go through the last six months of sales notes, security questionnaires and support tickets for SSO, SCIM, audit logs, session controls and custom login requirements. Count the ones you answered with “not yet” or “with custom work”.
- Estimate the engineering time already spent working around it. Lambda triggers, custom UI, tenant-mapping code and per-customer SSO setup all count. If one engineer spends a meaningful part of their time on identity plumbing, that cost belongs in the comparison alongside the invoice.
If you want to compare what running your own identity server would cost, our breakdown of self-hosted versus managed authentication costs covers infrastructure, engineering time and the costs people forget, such as upgrades and on-call.
Should you stay on Cognito?
For a lot of teams, staying is still the right call. If your product is consumer-facing, your users sign in directly, your enterprise customers are few, and nobody is waiting on an identity feature, Cognito’s model is hard to beat on simplicity. The point of running the checks above is to make that decision on purpose, with numbers, instead of discovering the answer at a renewal or in a stalled deal.
If the checks point the other way, the options range from restructuring how you use Cognito to moving to a different identity platform. Keycloak, the open-source identity server, is one of the common destinations for teams that want enterprise SSO, SCIM and fine-grained login control without per-MAU pricing. Our Keycloak versus Cognito comparison and our Cognito to Keycloak migration guide cover what that involves, and our pricing page shows how we price managed Keycloak.
Frequently asked questions
How much does AWS Cognito cost?
As of September 2026, AWS’s pricing page lists a 10,000 MAU monthly free tier for direct and social sign-ins on Lite and Essentials, then $0.015 per MAU on Essentials, and $0.020 per MAU with no free tier on Plus. SAML or OIDC federated users are free up to 50 MAUs, then $0.015 each.
Why is AWS Cognito expensive for B2B SaaS?
It is often not expensive at small scale. It becomes more noticeable for B2B products because every employee of an enterprise customer who signs in through that customer’s identity provider counts as a federated MAU at $0.015 beyond the first 50, so cost tracks customer headcount rather than contract value.
What counts as a monthly active user in Cognito?
According to AWS’s Cognito FAQ, a user counts as active in a calendar month when your app generates an identity operation for them, such as sign-up, sign-in, sign-out, token refresh, a password or attribute change, or an administrative lookup like AdminGetUser. Users with no such operation that month are not billed, so activity matters more than total accounts.
Does Cognito support enterprise SSO?
Yes. Cognito user pools support federation with SAML 2.0 and OpenID Connect identity providers, and federated users are billed separately at $0.015 per MAU beyond a 50-user free tier. The work for a multi-tenant SaaS product is designing how each customer’s identity provider maps to user pools and app clients.
When should you move off Cognito?
Consider it when an enterprise deal is blocked by an identity feature, when your team spends significant time building workarounds, or when your projected bill at several times today’s users is out of line with your plans. If none of those is true yet, staying and rechecking at each renewal is a reasonable choice.
Sources
- AWS, “Amazon Cognito Pricing”, retrieved 2026-09-29, https://aws.amazon.com/cognito/pricing/
- AWS, “Monitoring and managing costs”, Amazon Cognito Developer Guide, https://docs.aws.amazon.com/cognito/latest/developerguide/tracking-cost.html
- AWS, “Announcing new feature tiers: Essentials and Plus for Amazon Cognito”, AWS What’s New, 2024-11-22, https://aws.amazon.com/about-aws/whats-new/2024/11/new-feature-tiers-essentials-plus-amazon-cognito/
- AWS, “User pool feature plans”, Amazon Cognito Developer Guide, https://docs.aws.amazon.com/cognito/latest/developerguide/cognito-sign-in-feature-plans.html
- AWS, “Amazon Cognito FAQs” (definition of a monthly active user), https://aws.amazon.com/cognito/faqs/
- AWS, “Multi-tenant application best practices”, Amazon Cognito Developer Guide, https://docs.aws.amazon.com/cognito/latest/developerguide/multi-tenant-application-best-practices.html
- AWS, “Amazon Cognito removes Machine-to-Machine app client price dimension”, AWS What’s New, November 2025, https://aws.amazon.com/about-aws/whats-new/2025/11/amazon-cognito-removes-machine-machine-app-client-price-dimension/