Prompt
I'm frustrated with Cognito setup for social login
Latest observation
Oct 6, 2026
OpenAI APIWeb search: off
Totally fair — Cognito can be a pain for social login. It’s powerful, but the setup often feels overly fragile and scattered across the AWS console, IdP settings, app client settings, callback URLs, and hosted UI.
A lot of the frustration usually comes from one or more of these:
- Redirect URI mismatch between Cognito, Google/Apple/etc., and your app
- App client misconfiguration: wrong allowed callback/logout URLs, scopes, or OAuth flow
- Hosted UI quirks: works in one environment but not another
- Identity provider config not matching exactly what Cognito expects
- Token/session confusion: ID token vs access token vs refresh token
- Attribute mapping issues causing missing email/name/sub or account linking surprises
- Local dev pain because social login wants HTTPS and stable redirect URLs
If you want, I can help you untangle it quickly. The fastest way is if you paste:
- Which provider you’re using
- Google / Apple / Facebook / Amazon / etc.
- Your app type
- React / Next.js / mobile / backend-only / SPA
- What’s failing
- redirect error, invalid_client, mismatch_redirect_uri, blank page, login succeeds but no tokens, etc.
- Any exact error text
- What you want the flow to be
- Cognito hosted UI
- direct provider login
- backend exchanging code
- federated login into your own session
If you want, I can also give you:
- a minimal working Cognito + Google setup checklist
- a debug checklist for common social login errors
- or help you replace Cognito Hosted UI with a simpler auth approach if that’s the real source of pain.