How do configure dentitypool to use role from Token through *cloudformation in sam template*

I want to create the Cognito Identity Pool configuration as shown in the picture.

enter image description here

I have tried many options suggested at different places and AWS documentation has managed to completely got lost.

Any help .. much appreciated!

