TL;DR - Verified Google tokens server-side, created Cognito users via admin APIs with email_verified: true, generated deterministic passwords from user IDs + a server secret, and bypassed Cognito's hosted UI entirely. Works for signup and sign-in. Not for everyone, but perfect when you can't use Cognito's standard federation. The Constraint: No Console Access, No Hosted UI I inherited a broken