Udibo vs Amazon Cognito
Amazon Cognito is the user directory of AWS: 10,000 monthly active users free on its Lite and Essentials plans, SAML federation on every plan, and native hooks into IAM, API Gateway, and Lambda. Udibo gives you hosted sign-in behind a standard OAuth 2.0 boundary, with organizations, custom roles, and per-resource permissions included as a product rather than a pattern you assemble. The difference that decides most evaluations: Cognito prices the user and leaves the organization model, the authorization model, and the messaging bill to you; Udibo prices growth and includes those.
Checked September 7, 2026 against Amazon Cognito's pricing page and Amazon SES pricing. Udibo Identity is in private beta, and its prices are a preview, not an adopted rate card.
The short version
| If you need | Start with |
|---|---|
| Authorization already expressed in IAM, API Gateway authorizers, and Lambda | Cognito |
| SAML federation or passkeys at launch | Cognito, or another provider that ships them today |
| Fewer than about 10,000 users and no organization model | Cognito, whose free allowance covers all of them |
| Organizations with invitations, members, and roles as a product | Udibo |
| Permissions checked on your server, per organization or per resource | Udibo |
| Audit history and hosted-page branding without a plan change | Udibo |
| One bill without SES, SNS, or Lambda line items | Udibo |
| A production dependency available today without beta access | Cognito, until the Udibo hosted service opens to the public |
Why teams pick Udibo over Amazon Cognito
Organizations are a product, not a pattern. AWS documents multi-tenancy as approaches you implement: a user pool, an app client, a group, or a custom attribute per tenant (multi-tenancy guidance). Udibo ships organizations with invitations, memberships, and roles on every plan, with no cap on organizations or members, and a person can hold a different role in each.
Roles and permissions your server can enforce. A Cognito group carries a name, a precedence, and an optional IAM role; your API reads the
cognito:groupsclaim and decides what it means, and anything finer is a pre-token-generation Lambda function or a separate AWS service (groups). Udibo lets you register the permissions your application interprets, attach them to roles across a tenant, inside an organization, or on one resource, and read the result from the token or a hosted check.A record without a plan change. Cognito's user activity logs and their export are on Plus, which has no free allowance. Udibo keeps at least 90 days of audit history on every plan, exportable as CSV or NDJSON.
Your brand at the door on Free. Cognito's managed login takes CSS on every plan and its visual editor on Essentials and Plus. Udibo puts your name, logo, and colors on the hosted pages with no vendor badge on any plan.
One bill, three meters. A Cognito bill for a working product also carries SES for email, SNS for SMS, Lambda for triggers, and $0.00225 per machine-to-machine token, and a user bills as active on any identity operation, including "administrative creation or update" and "an attribute query on a user". Udibo's preview meters retained users, hosted permission checks, and the emails it sends for you; your own email sender is never metered.
Growth costs less past the free allowance. Udibo's preview rate is $3 per 1,000 retained users above its allowance. Cognito Essentials is $0.015 per user, or $15 per 1,000; Lite is $5.50 per 1,000 and then $4.60, without passwordless codes, passkeys, or the branding editor. At 100,000 users that is about $290 on Udibo, $1,350 on Essentials, and $495 on Lite, before email.
Why Amazon Cognito may still be the right choice
You are already on AWS. API Gateway authorizers, ALB authentication, Lambda triggers, and identity pools that exchange a sign-in for temporary AWS credentials make Cognito the native fit when your authorization is written in IAM. Udibo issues no IAM credentials.
10,000 users free, indefinitely. Lite and Essentials include 10,000 monthly active users at no charge, and the page says the free tier does not expire. Udibo's Free plan stops at 500 retained users, and its Standard plan does not become the cheaper bill until somewhere past 10,000 users.
SAML federation and passkeys today. SAML and OIDC federation are on every Cognito plan at $0.015 per federated user after 50 free; passkeys are on Essentials and Plus. Udibo does not offer SAML, SCIM, or hosted passkeys today.
MFA is on every Cognito plan too. Authenticator-app and SMS one-time codes are on Lite, Essentials, and Plus, so MFA alone is not a reason to switch. Udibo's MFA is authenticator apps with recovery codes.
Generally available. Cognito is a production dependency you can adopt this afternoon. Udibo Identity is in private beta.
Pricing side by side
Cognito bills a monthly active user, defined on its page as any user with an identity operation in a calendar month, including "administrative creation or update" and "an attribute query on a user". Udibo's preview bills a retained user: "A person who returns more than 24 hours after creating their account counts once in that UTC calendar month." The examples below assume the two counts are equal, which favours Cognito.
| You need | Udibo (preview) | Amazon Cognito |
|---|---|---|
| Free plan | 500 retained users, 25,000 hosted permission checks, 1,000 emails | 10,000 monthly active users on Lite and Essentials, none on Plus; 50 for SAML/OIDC federation; the free tier does not expire |
| First paid plan | $5 a month plus usage: 5,000 users, 250,000 checks, 10,000 emails included | No base fee: Lite $0.0055 per user past 10,000 and $0.0046 past 100,000; Essentials $0.015 per user past 10,000; Plus $0.020 from the first |
| Multi-factor authentication | Included on Free | Authenticator app and SMS codes on every plan; email codes on Essentials and Plus; SMS billed through Amazon SNS |
| Custom roles and permissions | Included on Free | Groups on every plan at no charge; roles and permissions are yours to build from the cognito:groups claim, a Lambda trigger, or a separate service |
| Organizations and members | No cap | No organization object; documented patterns using a user pool, app client, group, or attribute per tenant |
| Hosted page branding | Your name, logo, and colors with no vendor badge, on Free | CSS on every plan; the visual editor on Essentials and Plus |
| Custom session lifetime | Included on Free | Token expiry configurable in minutes, hours, or days; the managed login session cookie is fixed at one hour |
| Enterprise SSO connections | No per-connection fee for OpenID Connect providers; SAML not yet available | SAML and OIDC federation on every plan; $0.015 per federated user after 50 free |
| Audit or application log history | At least 90 days on every plan | User activity logs and their export on Plus |
| Sign-in email | 2 per retained user included, then $1 per 1,000; your own sender is free | Amazon SES at $0.10 per 1,000 messages à la carte |
| Users beyond the allowance | $3 per 1,000 retained users | Essentials $15 per 1,000; Lite $5.50 per 1,000, then $4.60 past 100,000; Plus $20 per 1,000 |
| Hosted permission checks | $10 per 1,000,000 past the allowance | No equivalent in Cognito; Amazon Verified Permissions is a separate service billed per request |
| Machine-to-machine tokens | No per-token charge; technical and abuse limits apply | $0.00225 per successful token response |
Three worked examples, with the same assumptions on both sides:
| Scenario | Udibo (preview) | Amazon Cognito |
|---|---|---|
| Consumer app: 10,000 retained users, 5,000 sign-in emails, MFA on, your own branding | $20 (Standard base plus 5,000 users above allowance) | $0.50 (10,000 users inside the free allowance on Lite or Essentials; 5,000 emails through SES at $0.10 per 1,000) |
| B2B app: 200 users, 5 organizations of 30 members, custom roles, MFA | $0 on Free, or $5 on Standard | $0 for users; the organization and role model is yours to build from groups, attributes, and a pre-token-generation Lambda function, billed as Lambda |
| Consumer app at 100,000 retained users | About $290 | Essentials: 90,000 × $0.015 = $1,350; Lite: 90,000 × $0.0055 = $495, without passwordless codes, passkeys, or the branding editor; plus SES email |
Sources: Amazon Cognito pricing, Amazon SES pricing, Amazon SNS SMS pricing (per-country rates, no single figure), Amazon Verified Permissions pricing, and Udibo's pricing preview. Token expiry and the session cookie are from AWS's token expiration and multi-tenancy guidance pages. All of them change; check the vendor's current page before you decide.
Cost at scale
Users only, same definition on both sides, on the plan that gives you MFA and your own branding. Udibo's figures are preview rates; the vendor's are its published list on the date above.
| Users | Udibo (preview) | Cognito Essentials | Cognito Lite |
|---|---|---|---|
| 1,000 | $5 (Standard) | $0 | $0 |
| 10,000 | $20 | $0 | $0 |
| 100,000 | About $290 | $1,350 | $495 |
| 1,000,000 | About $2,990 | $14,850 | About $4,635 |
Email through SES and SMS through SNS are extra on every Cognito row. Cognito is cheaper below roughly 12,000 users on Essentials and 18,000 on Lite; Udibo is cheaper above that.
What the integration looks like
With Udibo, register an application and its callback, send people to the hosted sign-in page, and finish the authorization-code flow on your server. Your backend holds the session and the browser gets a cookie, never a token. The first-login guide walks each checkpoint, and the organizations and permissions guides cover a person with a different role in each of two organizations.
With Cognito, create a user pool and an app client, send people to managed login or call the user pools API from an SDK, and validate the returned tokens in your API, natively through an API Gateway authorizer. Some choices need to be correct before users arrive: AWS documents that you cannot later change the username and alias configuration or the required attributes, or remove or redefine a custom attribute (user attributes). Josh Karamuth's July 2026 account and the linked HN discussion report setup, SDK-migration, and configuration difficulty alongside people for whom Cognito has worked well; they are reported experiences, not a benchmark of either product.
For either provider, rehearse email verification, password recovery, a changed profile field, and logout before choosing. A valid token says who someone is; your backend still decides what they may read.
Where Udibo needs a closer look
Udibo does not currently offer hosted passkeys, SAML, or SCIM. It issues no IAM
credentials, so an application whose authorization lives in IAM policies keeps
that layer or redesigns it. Udibo's webhooks are signed
notifications delivered after the fact, with retries and redrive; there is no
synchronous hook in the sign-in path, so anything a Lambda trigger changed
inline needs a different design. Tenant-management calls need administrator
credentials rather than an application's machine token, and the @udibo/oauth2
package is a separate operating model, not a self-hosted user pool. Test the
whole account journey before committing; a successful login alone does not
establish parity.
Moving an existing Cognito application
Both products are OpenID Connect issuers, so the boundary change is an issuer change rather than a rewrite. Inventory user pools, app clients, identity pools, Lambda triggers, custom claims, groups, and every IAM or application rule that depends on them. Preserve your own user IDs and map the old issuer and subject to the new one explicitly; do not use email alone as an account-linking rule. Decide what each group becomes: an organization, a role, or a permission a role carries.
Credential migration deserves a rehearsal. Cognito now supports password-hash import; importing into Cognito does not establish exportability from it, and AWS's profile-export guidance does not replicate passwords and assigns new subjects on restoration. Check the actual export against Udibo's supported import formats, plan a re-enrollment path for MFA and sessions, and retest every trigger-dependent behavior. Follow the migration guide before routing a cohort to the new issuer.
Try next: complete one Udibo login, then give a person two organizations and a different role in each. If you are on the waitlist, the agent integration brief lets your coding assistant prepare the integration in the meantime.
Frequently asked questions
Is Udibo cheaper than Cognito? Under about 10,000 users, no: Cognito's free tier covers them and SES email costs cents. Above that Cognito's $0.015 per user (Essentials) is five times Udibo's preview rate, before SES, SNS, and the Lambda triggers an organization model usually needs.
Does Udibo have organizations like Cognito groups? Cognito has groups and attributes; the organization model, invitations, and per-organization roles are yours to assemble with Lambda triggers. Udibo ships organizations, invitations, memberships, roles, and per-resource permissions as a product, with a hosted check your backend can call.
Can I move from Cognito to Udibo? Cognito does not export password hashes, so passwords cannot be imported; profiles and federated identities can, and users set a new password or sign in with a linked provider on first return. See migration planning.
Does Udibo integrate with IAM or API Gateway authorizers? Not natively. Udibo issues standard OAuth 2.0 tokens; an API Gateway JWT authorizer can validate them like any OpenID Connect issuer, but there is no IAM role mapping.
Last verified 2026-09-07.

