Auth0 to Cognito Migration
Context
Authentication infrastructure rarely appears in design portfolios because most authentication projects are framed as engineering problems: a supplier swap, a technical migration, a cost exercise. This one arrived the same way.
The migration touched millions of registered customers across 12 regional rollouts. At that scale, any meaningful drop-off in authentication flows represents direct customer acquisition loss.
Challenging the Brief
The initial framing was to migrate from Auth0 to AWS Cognito, maintain the existing experience, and avoid drop-off. The constraint set was significant: no custom fonts, limited error state control, restricted UI customisation within Cognito's hosted UI.
Before accepting those constraints as fixed, I requested AWS environment access and reviewed the actual Cognito capability set directly. That investigation revealed the brief had been built on an assumption: that Cognito's limitations were absolute. That turned out not to be fully accurate. Some constraints were real. Others were negotiable with the right technical approach. I wrote up the distinction and used it to reopen the scope conversation.
What I Pushed For — And What Didn't Make It
The capability review opened a conversation about what authentication could be, not just what it had to maintain. I advocated for two additions: magic links and social login.
Magic links would have reduced friction for returning users. Social login via Google and Apple would have reduced registration abandonment on mobile. Neither made it into the build. The PM deprioritised magic links on implementation complexity relative to the migration timeline. Social login was deferred. The migration was treated as a like-for-like swap to minimise risk, with improvements sequenced separately.
I disagreed with both calls but understood the reasoning. I wrote up the case for both and made sure they entered the product backlog with the original rationale attached.
North Star and Sequencing
I designed a North Star authentication experience: the version built without timeline or technical constraints. It gave the team a shared picture of the destination and made the sequencing decisions legible rather than arbitrary.
The phased delivery plan was signed off by the PM, Trade, and Engineering. Engineering pushed for single-phase delivery to reduce integration complexity. Trade wanted registration prioritised first given its direct impact on new customer acquisition. I resolved the disagreement by sequencing based on customer journey criticality, starting with the flows most users encounter most often, deferring lower-frequency flows to subsequent phases.
App Platform
The migration covered web and the JD Sports iOS and Android app. Once it was clear a custom UI wasn’t going to be funded for web, the app ceiling was set by the same constraint. I designed within it rather than advocate for investment that had no realistic path to approval.
On Android I designed a separate flow accounting for the absence of Apple Sign-In. Treating both platforms as identical would have left Android users with an unexplained gap. The Android authentication experience was designed as coherent in its own right.
Outcome
The migration delivered without measurable drop-off across authentication flows. Maintaining baseline performance through a full supplier change touching millions of registered customers was the right definition of success for this phase.
What matters more long term is the backlog that now exists for authentication improvements. Magic links and social login are defined, scoped, and ready for prioritisation. The migration created the foundation; the roadmap exists to build on it.
What This Changed Organisationally
Authentication improvement roadmap created where none previously existed. Magic links and social login scoped and backlogged with documented rationale
North Star design used as a sequencing framework, establishing a model for phased delivery decisions on the product team
Constraint investigation approach of requesting direct environment access before accepting a technical brief, adopted as a practice on subsequent infrastructure-adjacent projects
Key Decisions I Personally Drove
Challenged the constraint set by requesting direct AWS environment access before accepting the brief
Identified which Cognito limitations were real versus negotiable
Advocated for magic links and social login and ensured both entered the backlog with documented rationale
Designed the North Star experience that gave the team a shared destination
Resolved the Engineering vs Trade sequencing disagreement using customer journey criticality as the framework