This article introduces the inbound federation Lambda trigger for Amazon Cognito, enabling programmatic control over federated authentication flows. The post covers two primary use cases: filtering oversized group attributes from enterprise SAML providers to comply with Cognito’s attribute size limits, and automatically linking federated identities to existing local accounts based on email addresses to prevent duplicate accounts.