Is this similar to GCP's "Cloud Identity-Aware Proxy"?
Amazon's solution seems to integrate with a few other identity providers and gives the developers the tools to do authorization after authentication is done. It seems to position this more like a B2B2C. Although it feels like it already subsumes Google's IAP by doing so.
This is my understanding by reading the article on Amazon, I haven't actually used it.