Thanks for your questions! It's good feedback that there's no security documentation up yet. We have a lot more content coming live in the next few weeks - but let me try to hit some of the most important points:
* Session management is handled with secure, httpOnly cookies. We have you set a CNAME in production so we can set cookies in a first-party context (SameSite=Lax). * Cookies are scoped only to domains that require authentication data. If your backend is on api.example.com and you're running hosted Wordpress blog on blog.example.com, Wordpress won't receive your session cookies. * Passwords are bcrypted * All frontend-facing endpoints have CSRF protection enabled
Please let us know if there is anything specific we can help clarify. We've gotten into the nitty gritty so there's a lot to document, and it would be great to understand what areas to surface most prominently.
Here's a good reference: https://trust.okta.com
Also note that the cookies should be http only and with the secure flag
For web browsers, cookie-based auth solves a ton of browser-specific problems that history has spent a long time building up answers for.
Do I trust a new service or continue with one of the most trusted service from AWS?
I think that honestly, the biggest sell for a lot of newcomers is gonna be "you don't need to know AWS!" -- in my (very limited!) experience, if you want to do X with AWS, you're gonna need to learn how to do W, Y, Z, and maybe A and B with AWS too.
AWS moves so quickly I think it would be a disadvantage to rely on a smaller, unknown 3rd party that tries to replace itself as AWS.