NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
pub.dev · #805 most downloaded on pub.dev
Unofficial Amazon Cognito Identity Provider Dart SDK, to add user sign-up / sign-in to your mobile and web apps with AWS Cloud Services. Based on amazon-cognito-identity-dart
Last release 1 months ago
29 Aug 2026
Release timing varies
gaps range from 3 weeks to 1.2 years
Nearly every release is documented
notes for 59 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
7 years old
80 releases · first in 2019
fix: RandomString.generate() to include the last character from charList
breaking: CognitoMemoryStorage no longer uses a single library-level map shared by all instances (issue #277). Each CognitoMemoryStorage now has its o
CognitoMemoryStorage no longer uses a single library-level map shared by all instances (issue #277). Each CognitoMemoryStorage now has its own in-memory map. Code that created multiple CognitoMemoryStorage objects and relied on them seeing the same keys (or on clearing one instance affecting another) must be updated: use one shared instance, inject a custom CognitoStorage implementation, or merge migration data explicitly. Typical usage with a single storage instance per app is unchanged.One column per quarter.
feat: CognitoUser.getTokensFromRefreshToken for the GetTokensFromRefreshToken API (required for refresh token rotation). With rotation, reuse of an in
CognitoUser.getTokensFromRefreshToken for the GetTokensFromRefreshToken API (required for refresh token rotation). With rotation, reuse of an invalidated refresh token is reported as RefreshTokenReuseException on the clientfeat: new password challenge support
fix: confirmPassword returns response rather than always true
fix: confirmPassword returns response rather than always true
feat: email OTP MFA support
bumped: flutter_lints from 4.0.0 to 5.0.0
feat: upgraded associateSoftwareToken and verifySoftwareToken to use AssociateSoftwareToken with either an access token or a session string
bumped: flutter_lints from 3.0.2 to 4.0.0
Nothing published for this version
added: ClientMetaData to a parameter of respondToAuthChallenge
added: optional Refresh Token revocation on sign-out
- added: secret hash in SMS MFA
- bumped: js from 0.6.7 to 0.7.0
fixed: username assignment during _authenticateUserDefaultAuth in CognitoUser
http dependency includes older 0.13.1 version as valid
http dependency includes older 0.13.1 version as valid
dependencies are updated to the latest
fixed: SocketException when network is disabled
changed: a specific exception CognitoUserDeviceConfirmationNecessaryException that can be handled whenever an users device needs confirmation is separ
CognitoUserDeviceConfirmationNecessaryException that can be handled whenever an users device needs confirmation is separated from CognitoUserConfirmationNecessaryExceptionadded: better handling of unverified phone numbers using sms mfa
fixed: CognitoUser.getSession throws TypeError when storage returns null for clockDrift
feat: try to refresh session if access token is null
fixed: clientSecret instead of client secret hash in refresh session
added: secret hash to sendNewPasswordRequired function
added: Regen SECRET_HASH using the srp username
breaking: confirmRegistration forceAliasCreation parameter as named
fixes: SECRET_HASH parameter in CognitoUser refreshSession()
CognitoUser refreshSession()adds: optional clientMetadata (Map ) to signup
fixed: unexpected nullref during "initiateAuth" (authParameters is optional parameter in AuthenticationDetails)
changed: SocketException detecting via pattern (removed dart:io dependency)
added: flutter_test dev dependency
- added: flutter sdk dependency
- added: flutter dependency
deprecated pedantic replaced with flutter_lints + code style
Changed: exports client.dart to facilitate using injection for automated testing
Changed: SigV4Request headers is case insensitive
Removed: Temporary workaround to BigInt.modPow
Changed: challengeName as nullable variable
- Storage initialization fixes
Nullsafety branch is merged with latest non-nullsafety changes
Fixed: Retrieving data from Storage as FutureOr breaks clients
FutureOr<String?> breaks clientsshared_preferences as actual dependency, remove private file .flutter-plugins-dependencies and change code to work with latest http- Fixed: http.post Uri argument
Added optional validationData parameter for sendCustomChallengeAnswer
sendCustomChallengeAnswer- Initial null safety
[Issue #69] Solving "type '_InternalLinkedHashMap ' is not a subtype of type 'String' of 'value'" bug when ParamsDecorator receives a Map .
Example update: check for InvalidPasswordException in signup screen
Added optional validationData parameter for sendCustomChallengeAnswer
sendCustomChallengeAnswerDefined a local variable srp_username, in order to not override user value
srp_username, in order to not override user valueFixed: broken lastAuthUser lookup in CognitoUser
[Issue #69] Adding await in the call to analyticsMetadataParamsDecorator in case some implementations need to include async modifier
[Issue #88] Update example to latest version of Flutter for iOS, Android and Web. Uses AndroidX now which solves this issue
[Issue #103] Set confirmed to true when email or phone_number is verified
[Issue #69] Propagating analyticsMetadataParamsDecorator to CognitoUser from CognitoUserPool
[Issue #69] Adding support for AnalyticsMetadata request parameter
failed AWS request with specific character
removed: getLargeAValue call on AuthenticationHelper initialization
getLargeAValue call on AuthenticationHelper initializationadded: additional getters for CognitoJwtToken
added: SecretHash to ConfirmSignUp/ResendConfirmationCode request parameters
added: clear the cached clockDriftKey
added: Using an app client secret with '_authenticateUserPlainUsernamePassword'
fixed: CognitoUser.getCachedDeviceKeyAndPassword as a Future
added: CognitoUser.getDeviceKey method
changed: CognitoUser.updateAttributes and CognitoUser.deleteAttributes return Future
Your coding agent can read these notes before it upgrades. Set up the MCP server →