Residents should sign into the parks mobile app with the city’s existing social/OIDC identity provider without the app storing passwords. Which approach fits?
Select an answer to reveal the explanation.
Short Explanation
Don’t invent a password vault for the parks app. Federate through Cognito to the city’s existing IdP so residents sign in there—and your app never sees a password.
Full Explanation
Amazon Cognito supports federation with social and OIDC identity providers so applications authenticate users without storing passwords. Custom password stores increase risk and ops burden; shared IAM keys in mobile apps are unsafe; open APIs without auth are not acceptable for resident accounts.