Configuring AWS Cognito as OpenID for Access



I’m trying to configure cloudflare access to use AWS Cognito as it’s OpenID provider. I’m getting ‘something went wrong’ which seems to imply I’m missing something.
AWS documentation is really lacking here, so if someone achieved this I’ll be glad to know what the right configuration is.


