Cognito DR Demo

Reference SPA for the multi-region Cognito disaster-recovery drill harness. See the repository for architecture and runbooks.

Configured: DNS resolves to:

Sign in

Sign-in uses the CUSTOM_AUTH flow — your password is verified against an argon2id hash in DynamoDB, not Cognito's internal password store. See CUSTOM_AUTH_FLOW.md. If the Cognito pool's adaptive-auth risk engine flags your sign-in, an SMS MFA challenge is inserted after the password challenge — the wizard above handles that path.