1 article on this topic.
Don't build a custom identity provider for login. Use a real IdP for AuthN and keep authorization in your own control plane.