Load tests an Amazon Cognito user pool: the discovery document, the JSON web key set, and the hosted UI login page, token (client credentials) and userinfo endpoints. Cognito enforces request quotas, so use a test pool and watch for throttling responses.
It holds 11 ready-made jobs: 6 single scenarios and an enterprise test plan of 5 stages to run in order, 5 of them with pass/fail targets (SLOs). Each job is a plain request pattern you can change before running.
Scenarios include OIDC discovery document, discovery document (cache bypass), JSON web key set, hosted UI login page and hosted UI token: client credentials.
How to load test AWS Cognito
Open the template in BLASTA.
Set url, clientId, redirectUri, poolId and hostedUi to point at your own AWS Cognito system, ideally a staging copy.
Pick a job and choose the rate and duration.
Start the run and watch requests per second, latency percentiles and errors live; the result is saved to your history.
What you set before running
url
Issuer / base URL, no trailing slash
clientId
A test client registered for load testing
clientSecret
A credential, supplied as an environment variable and never typed into the form. Client secret. Read from the OIDC_CLIENT_SECRET env var by the CLI.
redirectUri
A redirect URI registered on that client
scope
Space-separated scopes, URL-encoded
token
A credential, supplied as an environment variable and never typed into the form. A valid access token. Read from OIDC_ACCESS_TOKEN by the CLI.
This is a hosted identity service: check the vendor's load-testing policy and your tenant's rate limits before running, keep the rate low, and expect 429s. Fetched by every relying party at start-up and on a timer. Cheap, but often served uncached.
This is a hosted identity service: check the vendor's load-testing policy and your tenant's rate limits before running, keep the rate low, and expect 429s. Forces the origin to build the document. Shows the cost behind a CDN or cache.
This is a hosted identity service: check the vendor's load-testing policy and your tenant's rate limits before running, keep the rate low, and expect 429s. Every API validating tokens locally refreshes keys from here, and a key rotation causes a thundering herd of fetches.
Enterprise plan, step 1 of 10. One request a second for 30 seconds. Run this first, every time: it proves the address, credentials and headers are right and that the environment is up before any real load is applied. Gate: zero errors. Reference request: OIDC discovery document. Hosted identity service: this stays well below the vendor's rate limits; check their load-testing policy first.
Step 2 of 10. About a fifth of normal traffic for 5 minutes: the uncontended latency of this request. Every later result is judged against it, so record p50 and p95. Gate: at most 0.5% errors and the default latency targets. Reference request: OIDC discovery document. Hosted identity service: this stays well below the vendor's rate limits; check their load-testing policy first.
Step 3 of 10. Normal busy-hour traffic for 10 minutes. The rate is the reference job's rate: raise it to your measured production peak-hour rate. This is the run that proves (or breaks) your SLO. Gate: at most 1% errors, p95 and p99 inside the targets. Reference request: OIDC discovery document. Hosted identity service: this stays well below the vendor's rate limits; check their load-testing policy first.
Step 4 of 10. Twice the average for 10 minutes: the busiest hour of the year plus headroom. Latency may rise, but must stay in SLO; if it does not, you have no headroom. Gate: at most 2% errors, latency targets doubled. Reference request: OIDC discovery document. Hosted identity service: this stays well below the vendor's rate limits; check their load-testing policy first.
Step 8 of 10, shortened for a hosted service. Steady load for 30 minutes to catch token or session expiry problems and slow decay on your side. Reference request: OIDC discovery document. Hosted identity service: this stays well below the vendor's rate limits; check their load-testing policy first.
Frequently asked questions
What does the AWS Cognito load test cover?
The AWS Cognito template has 11 jobs: 6 single scenarios and an enterprise test plan of 5 stages (smoke, baseline, load, stress, spike, soak, breakpoint and failover window). Scenarios include OIDC discovery document, discovery document (cache bypass), JSON web key set and hosted UI login page. 5 of them have pass/fail targets (SLOs), so a run can be judged against limits you set.
How do I load test AWS Cognito with BLASTA?
Open the template in BLASTA and set url, clientId, redirectUri, poolId and hostedUi, then pick a job and start it. Results stream live: requests per second, latency percentiles and errors, and the run is kept in your history. To run from the command line, use blasta preset new cognito with your address.
Is it safe to run the AWS Cognito load test against production?
Of the 11 jobs, 10 are read-only, 0 write data and 1 change state. Run the writing and state-changing jobs against a staging system, never against production data. Only test systems you own or have permission to test.
Set up a target above and press Start test. Charts and numbers appear here as the test runs.
Load generator resources
CPU used by BLASTA % of capacity
RAM used by BLASTA
Requests per second
Latency p95 lower is better
Response time
Status codes
Errors
Pick a template
Ready-made jobs for common systems. Search by system, protocol or what you want to test
(wordpress, saml, redis, spike, login storm…), pick a job, and it opens on the Test page ready to run.
You are browsing as a visitor: you can read every template and job. Sign in or create an account to use them.
No templates match
Try a shorter search, or a system name such as keycloak, postgres or soap.