In the bigger scheme of things, I envision a world where adding auth to your app (or any functionality) is as simple as adding a docker service.
In the bigger scheme of things, I envision a world where adding auth to your app (or any functionality) is as simple as adding a docker service.
Every component that gets added to your infrastructure is just "another thing" that you have to worry about in terms of uptime, monitoring, security, staying current, and so on. Personally, I'd rather not worry about any of that for something that isn't part of my core competency. Certainly there is a cost/benefit analysis to be made, mostly for larger companies.
I know we won't likely agree on this point, and that's ok! I just wanted to share an alternative perspective. :-)
Another reason: my app has no reason to send emails except for one thing: password resets. I don't want to set up a whole email flow just for that. By using a provider I can offload that at the same time.
Yeah, for the same reason I don't want to store credit card details, I don't want to store user credentials.
Only downside is the pretty ugly default login UI of cognito, but you can style it to some extend by adding a logo and custom css.
We (at Rownd) are looking into self-hosted, open-source options as well. What are a few features that are MUST haves?
There are some that are more complex (like SMS auth, email auth, etc). We want to 100% get away from passwords, so passwordless is critical since most passwords are security issues.