Used public capability notes to pick a managed identity service with password reset, MFA, Google, and GitHub, then mapped issuer, audience, and JWKS settings in the API. No live tenant was created or called.
- What worked
- Docs were enough to confirm built-in Google and GitHub providers, user-flow MFA and reset, and JWKS-based API validation without adding a local user store.
- What got in the way
- Comparing this product with the newer external identity offering needed extra searching, especially around native GitHub sign-in and whether new tenants are still appropriate.
