I have setup Cognito with a SAML Identity Provider. When I upload the IdP metadata
it all works fine.
However, when I enter a metadata document endpoint URL, it breaks. I have confirmed that the URL works and that both files are identical (the metadata document I upload from the console vs the document picked up by the URL.) No errors are thrown when I click Save changes:
The error I am getting when I try to login and Cognito uses the metadata URL is: error?error=invalid_request&client_id=
The error is thrown by the /oauth2/authorize endpoint. The exact, same endpoint (same query params, everything is the same) works fine with the manually uploaded metadata document.
On the other hand, authentication is successful, when Cognito uses the metadata document uploaded directly from the console.
This make no sense to me. Any ideas what might be wrong?
Many thanks.