A developer is building an application that uses Amazon Cognito for user authentication. The application needs to allow users to sign in with their existing Google accounts. Which action should the developer take to enable this?
Amazon Cognito user pools support federation with social identity providers like Google. By configuring Google as an identity provider in the user pool, users can sign in with their Google accounts. The developer must supply the Google app's client ID and client secret, which Cognito uses to validate tokens during the federation process.
Why this answer
Cognito user pools natively support federation with Google. Configuring Google as an identity provider in the user pool allows users to sign in with their Google credentials. Cognito handles the OAuth flow, token validation, and user profile creation, simplifying the integration.
Exam trap
The trap here is mixing up user pools and identity pools; identity pools are for AWS credentials, while user pools handle authentication and federation.