Through XQuery
- Last Updated: September 10, 2026
- 2 minute read
- MarkLogic Server
- Version 12.0
- Documentation
Note:
Run all code against the MarkLogic Server Security database.
To set up OAuth-based authentication and authorization with Amazon Cognito using XQuery through the Query Console, follow these steps:
-
Create the external security object by executing code like this:
Note:
The JWT Secrets field secures both symmetric and asymmetric signature keys.Note:
You can specify a JWKS URI to validate incoming JWT access tokens with JWKS instead of with JWT Secrets signature keys.Note:
The parameters$oauth-authorization-server-uri,$oauth-token-server-uri,$oauth-redirect-uri,$oauth-scope,$oauth-client-authentication-method, and$oauth-client-secretare required only when using the Authorization code flow. These parameters configure the MarkLogic app server to act as an OAuth client. They are not needed for the Resource server flow.Resource server flow
xquery version "1.0"; import module namespace sec = "http://marklogic.com/xdmp/security" at "/MarkLogic/security.xqy"; let $oauth-vendor := "Amazon Cognito", $oauth-flow-type := "Resource server", $oauth-client-id := "19vomjilg46bbvcpp9qcmeacoc", $oauth-token-type := "JSON Web Tokens", $oauth-username-attribute := "username", $oauth-role-attribute := "cognito:groups", $oauth-jwt-issuer-uri := "https://cognito-idp.us-east-1.amazonaws.com/us-east-1_fMQqTCMd9", $oauth-privilege-attribute := "", (:leave this empty for Cognito:) $oauth-jwt-alg := "RS256", $oauth-jwt-key-ids := "fBwvWl/oWKPB9fyhXtZ8EqAhAmljMhk4hW2dd/zpFYs=", $oauth-jwt-secret-values := "-----BEGIN PUBLIC KEY-----<PEM-converted RS256 JWT Secret Value>-----END PUBLIC KEY-----", $oauth-jwks-uri := "" let $oauth := sec:oauth-server( $oauth-vendor, $oauth-flow-type, $oauth-client-id, $oauth-token-type, $oauth-username-attribute, $oauth-role-attribute, $oauth-privilege-attribute, $oauth-jwt-issuer-uri, $oauth-jwt-alg, $oauth-jwt-key-ids, $oauth-jwt-secret-values) return sec:create-external-security( 'AmazonCognitoExampleOAuth', 'Amazon Cognito external security object for OAuth', 'oauth', 300, 'oauth', (), (), $oauth)Authorization code flow
xquery version "1.0"; import module namespace sec = "http://marklogic.com/xdmp/security" at "/MarkLogic/security.xqy"; let $oauth-vendor := "Amazon Cognito", $oauth-flow-type := "Authorization code", $oauth-client-id := "<application-client-id>", $oauth-token-type := "JSON Web Tokens", $oauth-username-attribute := "username", $oauth-role-attribute := "cognito:groups", $oauth-jwt-issuer-uri := "<jwt-issuer-uri>", $oauth-privilege-attribute := "", $oauth-jwt-alg := "RS256", $oauth-jwt-key-ids := "<key-id>", $oauth-jwt-secret-values := "-----BEGIN PUBLIC KEY-----<PEM-converted key>-----END PUBLIC KEY-----", $oauth-jwks-uri := "", $oauth-authorization-server-uri := "<oauth-server-authorize-endpoint>", $oauth-token-server-uri := "<oauth-server-token-endpoint>", $oauth-redirect-uri := "https://<marklogic-host>:<app-server-port>", $oauth-scope := "openid profile", $oauth-client-authentication-method := "Client secret", $oauth-client-secret := "<client-secret-value>" let $oauth := sec:oauth-server( $oauth-vendor, $oauth-flow-type, $oauth-client-id, $oauth-token-type, $oauth-username-attribute, $oauth-role-attribute, $oauth-privilege-attribute, $oauth-jwt-issuer-uri, $oauth-jwt-alg, $oauth-jwt-key-ids, $oauth-jwt-secret-values, $oauth-jwks-uri, $oauth-authorization-server-uri, $oauth-token-server-uri, $oauth-redirect-uri, $oauth-scope, $oauth-client-authentication-method, $oauth-client-secret) return sec:create-external-security( 'AmazonCognitoExampleOAuthClient', 'Amazon Cognito external security object for OAuth Authorization Code flow', 'oauth', 300, 'oauth', (), (), $oauth) -
Create any HTTP, XDBC, WebDAV, or ODBC app servers that you wish to configure with this external security object.
-
Configure your app servers to use this external security object with code like this:
xquery version "1.0-ml"; import module namespace admin = "http://marklogic.com/xdmp/admin" at "/MarkLogic/admin.xqy"; let $config := admin:get-configuration() let $groupid := admin:group-get-id($config, "Default") let $appserver := <app server name> let $extsec := "AmazonCognitoExampleOAuth" return admin:save-configuration(admin:appserver-set-external-security($config, admin:appserver-get-id($config, $groupid, $appserver), $extsec, fn:false(), "oauth")) -
Assign external names to your desired roles with code like this:
xquery version "1.0-ml"; import module namespace sec = "http://marklogic.com/xdmp/security" at "/MarkLogic/security.xqy"; let $role-name := <MarkLogic Server role name like "manage-user"> let $external-name := "GroupFoo" return sec:role-set-external-names($role-name, $external-name)
MarkLogic Server is now set up for OAuth-based authentication and authorization with Amazon Cognito.