MojoAuth vs AWS Cognito: pricing, developer experience, and migration
AWS Cognito is the default identity service for teams already on AWS. It is cheap at scale and integrates with the rest of the AWS surface. It is also famously hard to configure and slow to ship against. This comparison covers when Cognito is the right pick and when MojoAuth wins.
TL;DR verdict
Choose Cognito if your stack is deeply AWS-native, your team is comfortable with IAM policies and CloudFormation, and you need direct integration with Lambda and other AWS services. Choose MojoAuth if you want to deploy in hours, not months, transparent pricing, and a developer experience that does not assume an AWS background. The Cognito sweet spot is teams already deeply on AWS; for everyone else, MojoAuth is materially faster to ship.
At-a-glance comparison
From each vendor's current documentation. See the methodology for sourcing rules.
| Dimension | MojoAuth | AWS Cognito |
|---|---|---|
| Free tier | 25,000 MAUs | 50,000 MAUs (User Pool) |
| Pricing model | Published MAU tiers | Per-MAU + per-MFA + federation charges |
| Time to first login | Deploy in hours, not months | 1 to 4 hours (User Pool + IAM setup) |
| Passkeys / WebAuthn | FIDO2/WebAuthn compliant, built in | Supported via custom auth flow (2024) |
| WhatsApp OTP | Native channel (Enterprise) | Not available |
| Magic links | Native | Custom Lambda required |
| MFA methods | Authenticator OTP (TOTP), SMS, email, passkeys | TOTP, SMS, email |
| One Tap Login | Included | Custom build |
| Cloud portability | Any cloud / on-prem via Private Cloud (Enterprise) | AWS only |
| SDK ergonomics | Clean REST + 22+ SDKs | AWS SDK + amplify |
| SOC 2 Type II / ISO 27001 | Certified | AWS-wide compliance |
| HIPAA BAA | Enterprise plan (HIPAA-ready) | AWS BAA covers Cognito |
| Migration tooling | Bulk import + parallel run | Limited; custom Lambda for migration |
| Pricing transparency | Single line item | Multiple line items per behavior |
When to choose MojoAuth
You want to deploy in hours, not months.
Cognito's first-time setup involves creating User Pools, configuring app clients, writing IAM policies, defining custom auth flows (often via Lambda triggers), and managing CloudFormation if you want any of this versioned. MojoAuth's setup is an API key and an SDK install. For teams without deep AWS muscle, this difference is weeks of work.
You want pricing that does not behave like a phone bill.
Cognito charges for MAUs, MFA SMS, federations, advanced security features (per-MAU), and Identity Pool requests separately. The bill is hard to predict before launch. MojoAuth publishes MAU tiers (Free up to 25,000 MAU, Business Pro from $120/month) with passwordless methods included in the plan, so finance can budget.
You need passkeys, WhatsApp, or magic links out of the box.
Cognito added passkey support in 2024 but requires custom auth flow Lambda triggers to wire it together. WhatsApp OTP is not available. Magic links require custom Lambda. MojoAuth ships all three as native primitives (WhatsApp OTP on Enterprise).
When to choose AWS Cognito
Your stack is heavily AWS-native.
If your application servers, databases, and analytics all live in AWS, Cognito's IAM-native model fits the pattern your team already knows. Identity Pools also let you grant authenticated users temporary AWS credentials, which is unique to Cognito and useful for direct S3 or DynamoDB access from clients.
You need Lambda triggers in the auth flow.
Cognito offers 11 Lambda trigger points across signup, signin, and token issuance. If your custom auth logic is already implemented in Lambda functions, Cognito's native triggers are simpler than MojoAuth's webhook model.
Cost is the dominant factor at scale.
At very high MAU counts (hundreds of thousands or millions) with simple auth flows, Cognito's per-MAU pricing can come in lower than dedicated CIAM vendors. If you can absorb the engineering cost of running Cognito well, the raw price is attractive.
Pricing breakdown
Cognito's pricing has multiple line items. Numbers below are AWS list prices in the US East region as of the review date, with realistic assumptions about MFA SMS volume.
| Tier | MojoAuth | AWS Cognito (effective) |
|---|---|---|
| 1,000 MAUs | Free | Free |
| 10,000 MAUs | Free | ~$50-150/mo (User Pool + MFA SMS) |
| 100,000 MAUs | $380/mo (Business Pro) | ~$500-1,500/mo depending on usage profile |
What the line items mean
- User Pool MAUs. Anyone who authenticates in a billing month counts as one MAU. Standard tier costs apply above 50,000.
- Advanced security. Adaptive auth and compromised credentials check are an additional per-MAU charge.
- SAML and OIDC federations. Charged per active federation user per month.
- MFA SMS. Per-message pricing that varies by destination country. International apps hit this fast.
Developer experience
The biggest practical difference between these two platforms is the shape of the developer surface. Cognito assumes you are at home with AWS conventions. MojoAuth assumes you want to make HTTP calls.
Email OTP with MojoAuth
import { MojoAuth } from "@mojoauth/server-sdk";
const mojo = new MojoAuth({ apiKey: process.env.MOJOAUTH_API_KEY });
await mojo.email.sendOtp({ email: "user@example.com" });
const { user, accessToken } = await mojo.email.verifyOtp({
email: "user@example.com",
otp: req.body.otp,
});
Sign up with Cognito (AWS SDK v3)
import { CognitoIdentityProviderClient, SignUpCommand,
ConfirmSignUpCommand } from "@aws-sdk/client-cognito-identity-provider";
const client = new CognitoIdentityProviderClient({ region: "us-east-1" });
await client.send(new SignUpCommand({
ClientId: process.env.COGNITO_APP_CLIENT_ID,
Username: "user@example.com",
Password: tempPassword,
UserAttributes: [{ Name: "email", Value: "user@example.com" }],
}));
await client.send(new ConfirmSignUpCommand({
ClientId: process.env.COGNITO_APP_CLIENT_ID,
Username: "user@example.com",
ConfirmationCode: req.body.code,
}));
Practical observations:
- The Cognito example assumes you have created a User Pool, created an app client, configured the password policy, and possibly written custom auth Lambda triggers. The setup work happens before this code runs.
- Cognito's SDK calls feel like AWS SDK calls because they are. If your team writes AWS SDK code daily, this is fine. If not, the learning curve is real.
- Error handling is divergent. Cognito returns AWS service exceptions that need parsing for user-facing messages. MojoAuth returns structured errors with codes.
Security and compliance
MojoAuth posture
- SOC 2 Type II and ISO 27001 certified, PCI DSS compliant
- FIDO2/WebAuthn compliant passkeys
- HIPAA-ready (BAA on Enterprise)
- Independent identity-focused security program
- End-to-end TLS, AES-256 at rest
AWS Cognito posture
- SOC 1/2/3, ISO 27001/27017/27018, PCI DSS
- HIPAA-eligible under AWS BAA
- FedRAMP Moderate (Cognito in select regions)
- AWS-wide security operations
- End-to-end TLS, AES-256 at rest via KMS
Cognito has the broader certification footprint because of AWS's compliance investments. If FedRAMP is a hard requirement, Cognito is the obvious pick.
Migration from Cognito to MojoAuth
Most migrations complete in 2–3 weeks. Cognito migrations are slightly more involved than Auth0 migrations because of the password hash format and custom attribute handling.
- Week 1: export and import. Use the Cognito User Pool export feature (or AdminListUsers + custom export) to dump users with their custom attributes. MojoAuth imports the dataset including password hashes; users on subsequent login are transparently upgraded.
- Week 2: parallel run with feature flag. Update backends to verify MojoAuth JWTs instead of Cognito ID tokens behind a flag. Test in staging, then route a small percentage of production traffic.
- Week 3: cutover and decommission. Roll traffic to 100% MojoAuth. Replace any Lambda triggers (PreSignUp, PostAuth, etc.) with MojoAuth webhooks. Keep the Cognito User Pool for two weeks as fallback before deletion.
Common pitfalls
- Identity Pool users (the temporary-credentials side of Cognito) do not have a clean MojoAuth analog. If you grant clients direct AWS access via Identity Pools, plan a redesign.
- Cognito custom attributes prefixed with `custom:` need mapping to MojoAuth user metadata. Audit which attributes are read by downstream code before cutover.
- Lambda triggers on PreSignUp, PostAuthentication, and PreTokenGeneration are common. Each needs a webhook equivalent on MojoAuth.
Frequently Asked Questions
Ready to evaluate the migration?
Get started for free with 25,000 MAU, or talk to sales about your Cognito setup.
Sources
- AWS Cognito pricing page and documentation, accessed on the review date.
- AWS Artifact for SOC, ISO, and PCI DSS compliance evidence.
- AWS Cognito User Pool migration documentation.
- MojoAuth pricing page and Trust Portal.
- Hands-on testing of both SDKs by the editorial team on the review date.
Advocates for frictionless passwordless authentication and connects product outcomes to real buyer decisions in CIAM.
Builds developer-friendly passwordless authentication systems and reviews SDK ergonomics across vendors.