Skip to content

Udibo vs Amazon Cognito

Amazon Cognito is the user directory of AWS: 10,000 monthly active users free on its Lite and Essentials plans, SAML federation on every plan, and native hooks into IAM, API Gateway, and Lambda. Udibo gives you hosted sign-in behind a standard OAuth 2.0 boundary, with organizations, custom roles, and per-resource permissions included as a product rather than a pattern you assemble. The difference that decides most evaluations: Cognito prices the user and leaves the organization model, the authorization model, and the messaging bill to you; Udibo prices growth and includes those.

Checked September 7, 2026 against Amazon Cognito's pricing page and Amazon SES pricing. Udibo Identity is in private beta, and its prices are a preview, not an adopted rate card.

The short version

If you needStart with
Authorization already expressed in IAM, API Gateway authorizers, and LambdaCognito
SAML federation or passkeys at launchCognito, or another provider that ships them today
Fewer than about 10,000 users and no organization modelCognito, whose free allowance covers all of them
Organizations with invitations, members, and roles as a productUdibo
Permissions checked on your server, per organization or per resourceUdibo
Audit history and hosted-page branding without a plan changeUdibo
One bill without SES, SNS, or Lambda line itemsUdibo
A production dependency available today without beta accessCognito, until the Udibo hosted service opens to the public

Why teams pick Udibo over Amazon Cognito

  • Organizations are a product, not a pattern. AWS documents multi-tenancy as approaches you implement: a user pool, an app client, a group, or a custom attribute per tenant (multi-tenancy guidance). Udibo ships organizations with invitations, memberships, and roles on every plan, with no cap on organizations or members, and a person can hold a different role in each.

  • Roles and permissions your server can enforce. A Cognito group carries a name, a precedence, and an optional IAM role; your API reads the cognito:groups claim and decides what it means, and anything finer is a pre-token-generation Lambda function or a separate AWS service (groups). Udibo lets you register the permissions your application interprets, attach them to roles across a tenant, inside an organization, or on one resource, and read the result from the token or a hosted check.

  • A record without a plan change. Cognito's user activity logs and their export are on Plus, which has no free allowance. Udibo keeps at least 90 days of audit history on every plan, exportable as CSV or NDJSON.

  • Your brand at the door on Free. Cognito's managed login takes CSS on every plan and its visual editor on Essentials and Plus. Udibo puts your name, logo, and colors on the hosted pages with no vendor badge on any plan.

  • One bill, three meters. A Cognito bill for a working product also carries SES for email, SNS for SMS, Lambda for triggers, and $0.00225 per machine-to-machine token, and a user bills as active on any identity operation, including "administrative creation or update" and "an attribute query on a user". Udibo's preview meters retained users, hosted permission checks, and the emails it sends for you; your own email sender is never metered.

  • Growth costs less past the free allowance. Udibo's preview rate is $3 per 1,000 retained users above its allowance. Cognito Essentials is $0.015 per user, or $15 per 1,000; Lite is $5.50 per 1,000 and then $4.60, without passwordless codes, passkeys, or the branding editor. At 100,000 users that is about $290 on Udibo, $1,350 on Essentials, and $495 on Lite, before email.

Why Amazon Cognito may still be the right choice

  • You are already on AWS. API Gateway authorizers, ALB authentication, Lambda triggers, and identity pools that exchange a sign-in for temporary AWS credentials make Cognito the native fit when your authorization is written in IAM. Udibo issues no IAM credentials.

  • 10,000 users free, indefinitely. Lite and Essentials include 10,000 monthly active users at no charge, and the page says the free tier does not expire. Udibo's Free plan stops at 500 retained users, and its Standard plan does not become the cheaper bill until somewhere past 10,000 users.

  • SAML federation and passkeys today. SAML and OIDC federation are on every Cognito plan at $0.015 per federated user after 50 free; passkeys are on Essentials and Plus. Udibo does not offer SAML, SCIM, or hosted passkeys today.

  • MFA is on every Cognito plan too. Authenticator-app and SMS one-time codes are on Lite, Essentials, and Plus, so MFA alone is not a reason to switch. Udibo's MFA is authenticator apps with recovery codes.

  • Generally available. Cognito is a production dependency you can adopt this afternoon. Udibo Identity is in private beta.

Pricing side by side

Cognito bills a monthly active user, defined on its page as any user with an identity operation in a calendar month, including "administrative creation or update" and "an attribute query on a user". Udibo's preview bills a retained user: "A person who returns more than 24 hours after creating their account counts once in that UTC calendar month." The examples below assume the two counts are equal, which favours Cognito.

You needUdibo (preview)Amazon Cognito
Free plan500 retained users, 25,000 hosted permission checks, 1,000 emails10,000 monthly active users on Lite and Essentials, none on Plus; 50 for SAML/OIDC federation; the free tier does not expire
First paid plan$5 a month plus usage: 5,000 users, 250,000 checks, 10,000 emails includedNo base fee: Lite $0.0055 per user past 10,000 and $0.0046 past 100,000; Essentials $0.015 per user past 10,000; Plus $0.020 from the first
Multi-factor authenticationIncluded on FreeAuthenticator app and SMS codes on every plan; email codes on Essentials and Plus; SMS billed through Amazon SNS
Custom roles and permissionsIncluded on FreeGroups on every plan at no charge; roles and permissions are yours to build from the cognito:groups claim, a Lambda trigger, or a separate service
Organizations and membersNo capNo organization object; documented patterns using a user pool, app client, group, or attribute per tenant
Hosted page brandingYour name, logo, and colors with no vendor badge, on FreeCSS on every plan; the visual editor on Essentials and Plus
Custom session lifetimeIncluded on FreeToken expiry configurable in minutes, hours, or days; the managed login session cookie is fixed at one hour
Enterprise SSO connectionsNo per-connection fee for OpenID Connect providers; SAML not yet availableSAML and OIDC federation on every plan; $0.015 per federated user after 50 free
Audit or application log historyAt least 90 days on every planUser activity logs and their export on Plus
Sign-in email2 per retained user included, then $1 per 1,000; your own sender is freeAmazon SES at $0.10 per 1,000 messages à la carte
Users beyond the allowance$3 per 1,000 retained usersEssentials $15 per 1,000; Lite $5.50 per 1,000, then $4.60 past 100,000; Plus $20 per 1,000
Hosted permission checks$10 per 1,000,000 past the allowanceNo equivalent in Cognito; Amazon Verified Permissions is a separate service billed per request
Machine-to-machine tokensNo per-token charge; technical and abuse limits apply$0.00225 per successful token response

Three worked examples, with the same assumptions on both sides:

ScenarioUdibo (preview)Amazon Cognito
Consumer app: 10,000 retained users, 5,000 sign-in emails, MFA on, your own branding$20 (Standard base plus 5,000 users above allowance)$0.50 (10,000 users inside the free allowance on Lite or Essentials; 5,000 emails through SES at $0.10 per 1,000)
B2B app: 200 users, 5 organizations of 30 members, custom roles, MFA$0 on Free, or $5 on Standard$0 for users; the organization and role model is yours to build from groups, attributes, and a pre-token-generation Lambda function, billed as Lambda
Consumer app at 100,000 retained usersAbout $290Essentials: 90,000 × $0.015 = $1,350; Lite: 90,000 × $0.0055 = $495, without passwordless codes, passkeys, or the branding editor; plus SES email

Sources: Amazon Cognito pricing, Amazon SES pricing, Amazon SNS SMS pricing (per-country rates, no single figure), Amazon Verified Permissions pricing, and Udibo's pricing preview. Token expiry and the session cookie are from AWS's token expiration and multi-tenancy guidance pages. All of them change; check the vendor's current page before you decide.

Cost at scale

Users only, same definition on both sides, on the plan that gives you MFA and your own branding. Udibo's figures are preview rates; the vendor's are its published list on the date above.

UsersUdibo (preview)Cognito EssentialsCognito Lite
1,000$5 (Standard)$0$0
10,000$20$0$0
100,000About $290$1,350$495
1,000,000About $2,990$14,850About $4,635

Email through SES and SMS through SNS are extra on every Cognito row. Cognito is cheaper below roughly 12,000 users on Essentials and 18,000 on Lite; Udibo is cheaper above that.

What the integration looks like

With Udibo, register an application and its callback, send people to the hosted sign-in page, and finish the authorization-code flow on your server. Your backend holds the session and the browser gets a cookie, never a token. The first-login guide walks each checkpoint, and the organizations and permissions guides cover a person with a different role in each of two organizations.

With Cognito, create a user pool and an app client, send people to managed login or call the user pools API from an SDK, and validate the returned tokens in your API, natively through an API Gateway authorizer. Some choices need to be correct before users arrive: AWS documents that you cannot later change the username and alias configuration or the required attributes, or remove or redefine a custom attribute (user attributes). Josh Karamuth's July 2026 account and the linked HN discussion report setup, SDK-migration, and configuration difficulty alongside people for whom Cognito has worked well; they are reported experiences, not a benchmark of either product.

For either provider, rehearse email verification, password recovery, a changed profile field, and logout before choosing. A valid token says who someone is; your backend still decides what they may read.

Where Udibo needs a closer look

Udibo does not currently offer hosted passkeys, SAML, or SCIM. It issues no IAM credentials, so an application whose authorization lives in IAM policies keeps that layer or redesigns it. Udibo's webhooks are signed notifications delivered after the fact, with retries and redrive; there is no synchronous hook in the sign-in path, so anything a Lambda trigger changed inline needs a different design. Tenant-management calls need administrator credentials rather than an application's machine token, and the @udibo/oauth2 package is a separate operating model, not a self-hosted user pool. Test the whole account journey before committing; a successful login alone does not establish parity.

Moving an existing Cognito application

Both products are OpenID Connect issuers, so the boundary change is an issuer change rather than a rewrite. Inventory user pools, app clients, identity pools, Lambda triggers, custom claims, groups, and every IAM or application rule that depends on them. Preserve your own user IDs and map the old issuer and subject to the new one explicitly; do not use email alone as an account-linking rule. Decide what each group becomes: an organization, a role, or a permission a role carries.

Credential migration deserves a rehearsal. Cognito now supports password-hash import; importing into Cognito does not establish exportability from it, and AWS's profile-export guidance does not replicate passwords and assigns new subjects on restoration. Check the actual export against Udibo's supported import formats, plan a re-enrollment path for MFA and sessions, and retest every trigger-dependent behavior. Follow the migration guide before routing a cohort to the new issuer.

Try next: complete one Udibo login, then give a person two organizations and a different role in each. If you are on the waitlist, the agent integration brief lets your coding assistant prepare the integration in the meantime.

Frequently asked questions

Is Udibo cheaper than Cognito? Under about 10,000 users, no: Cognito's free tier covers them and SES email costs cents. Above that Cognito's $0.015 per user (Essentials) is five times Udibo's preview rate, before SES, SNS, and the Lambda triggers an organization model usually needs.

Does Udibo have organizations like Cognito groups? Cognito has groups and attributes; the organization model, invitations, and per-organization roles are yours to assemble with Lambda triggers. Udibo ships organizations, invitations, memberships, roles, and per-resource permissions as a product, with a hosted check your backend can call.

Can I move from Cognito to Udibo? Cognito does not export password hashes, so passwords cannot be imported; profiles and federated identities can, and users set a new password or sign in with a linked provider on first return. See migration planning.

Does Udibo integrate with IAM or API Gateway authorizers? Not natively. Udibo issues standard OAuth 2.0 tokens; an API Gateway JWT authorizer can validate them like any OpenID Connect issuer, but there is no IAM role mapping.

Last verified 2026-09-07.