I used AWS cognito for a startup. I wouldn't do it again
speckx
173 points
122 comments
August 28, 2026
Related Discussions
Found 5 related stories in 61.3ms across 4,827 title embeddings via pgvector HNSW
- Logging in Was Never Supposed to Be This Complicated bookofjoe · 14 pts · August 26, 2026 · 45% similar
- What's the best way to do authentication in modern applications freediver · 44 pts · July 11, 2026 · 44% similar
- Google Cloud is killing it beardyw · 16 pts · July 24, 2026 · 44% similar
- My friends all hate AI; I just joined an AI startup eamag · 37 pts · August 17, 2026 · 43% similar
- I got into YC Startup School by hacking it speckx · 102 pts · July 24, 2026 · 42% similar
Discussion Highlights (20 comments)
AndrewKemendo
Nobody is ever going to convince me AWS isn’t hostile to users as a filter Like how scammers put in typos
_3u10
Just use whatever service that costs 10x as much to make it do what it was advertised to do in the first place, like DAX for dynamo or cloudfront for S3 in case you hit “scale” like 2000 req/sec
turboturbo
This reads like, and is confirmed by Pangram to be, 100% AI slop
wilkystyle
> Reading Cognito docs feels like someone took three separate manuals, threw them in a blender, and then sprinkled in some outdated Stack Overflow answers for flavor. This is my experience with basically all of AWS documentation. It is nearly always either (1) far too high-level to be of any actual use, or (2) far too verbose, with a massive volume of superfluous information I need to parse and discard before I get to the stuff I am trying to figure out. As just one example, I recently needed to link an AWS Partner Central account with an AWS Management account, and process and documentation was painfully complicated: https://docs.aws.amazon.com/partner-central/latest/getting-s...
samdixon
Regardless of AI gen'd article... Cognito does have some rough edges. One day I'd like to make a best practices Cloudformation template (if doesn't already exist) that includes things like which login name to set, notification lambdas and the like. One big pro about cognito.. can't beat the price.
pelagicAustral
AWS documentation is the best excuse to stay away from their services. I thank everyday for their documents, it's like putting a lighthouse on an iceberg.
mikigraf
Don't even get me started on backups or other basic functionality one would expect from a service like this. AWS should either make an acquisition (Auth0 or a smaller company like Wristband?) and rebuild the service, or just kill it. Instead, we have a critical service that enterprises rely on stuck in limbo...
patwolf
My experience with Cognito matches the author's experience exactly. I mostly used Auth0 in the past, but we switched to Cognito for a new project because it would be cheaper. Don't like that email addresses are case sensitive, and now you want to change that? Sorry, you gotta create a new user pool from scratch--no way to migrate.
opengrass
LDAP, or... Linux/BSD as the identity/runtime layer, SSH is the protocol boundary, and your web backend is the command gateway.
solatic
> Next time, I’m picking a tool based on developer experience first, not AWS service integration convenience. The time we lost debugging Cognito issues could have paid for several years of a paid auth provider. How many paid auth providers let you export user password hashes so that you can seamlessly migrate to another vendor, if you want to? The whole problem with auth is that both (a) login screens are shown to unauthenticated users, which is a superset that includes attackers, who will do everything from DDoS to crafted malicious input to try to grab user secrets, so you really want to pick something that is already running at large production scale and with all the production battle-scars, and (b) that need to go with a managed vendor is very much in tension against local development, vendor independence, data portability, and other Good Engineering Practices (TM). Sure, AWS Cognito sucks. In many ways, the product feels stuck. Making compromises to get stuff shipped, working, and stable sucks. But honestly, unless you're going to prefer (b) over (a) (and there are times to do so, in particular with intranet applications behind a firewall that aren't really susceptble to those kinds of attacks) and pick something like Keycloak, you could do a lot worse than Cognito (shudder, Okta, shudder).
badrequest
IMHO not rolling your own auth is asking for stuff like this to happen.
duttish
I built a product on Cognito in 2017-18 or when it was, and already back then it felt semi-abandonded. Thankfully that particular product never really took off and we didn't have to spend too much time on wrangling Cognito.
hirako2000
AWS is mental health hazard, has been for many years.
klodolph
Feels like there are a few categories of services from cloud providers, There’s the basic infrastructure we know and love like S3, EC2, etc. There’s the higher level but still basic stuff that just makes a lot of sense. I like ECS + Fargate, Lambda, DynamoDB, SQS. And then there are the tarpits. CloudFormation. Cognito. Step Functions. API Gateway. They do something useful (otherwise why would they exist?) but the main point of their existence seems to be to trap you in AWS, and the fact that they solve a problem seems secondary. Some of them are cheap (CloudFormation is free!) but in general they seem like expensive alternatives to simpler, cheaper solutions.
jprokay13
I’ve been pondering a deep dive into Keycloak or Ory. Or is WorkOS good enough for the price? I’m looking to centralize account management across multiple systems.
andrewstuart
Why use any AWS for a startup? Why use AWS for any size company?
DerDerDaIst
I had the same learnings with cognito when using it for a product we built. We mainly choose it because AWS was used anyway and the security aspect seemed to be solved entierly with this coice (if aws get's hacked ... ). We regretted it out of similar reasons.
etothepii
I share the OP's pain we chose to use cognito for the exact same reason and I've had the exact same pain however the evaluation of itself takes time and the inconvenience OP is suffering with is only a function of having users. If I were starting my startup again I would, in almost every instance, trade problems if we have some success for reduced decision fatigue at the start.
rafaelmn
One greenfield project I worked on our AWS rep specifically told us to avoid Cognito and go towards auth0 or whatever else. On another project people didn't get this advice and we spent a two weeks working around the limitations to scrap it eventually.
skeeter2020
>> and even rawdogged a custom JWT system ... This may now mean something along the lines of "struggling to grind through..." but is based on the original meaning of having sex without a condom, typically with misogynist overtones. You might want to avoid it for this style of writing and audience.