Having said that, none of this prevents people from creating fake accounts. On our system I can see people regularly signin in with multiple google accounts, with incrementing digits in the name, trying to abuse the free tier. You'll need to build something yourself for that, depending on your risk surface. For us this involves tracking requests across IP addresses, blocking free access from data centre IPs, blocking bots using AWS WAF, analyzing task patterns to spot people who use multiple residential IPs and a bit more.
I'm sure many users prefer the Google/Github/Apple/Twitter? buttons, and the moment they see a email+password only wall they bounce, but I think that offering a username + auto suggested password is a superb UX.
I wanted to hear if someone who went this route later regretted it, or if they are happy with it and how they solved the problems that may appear. Mainly abuse and forgot password flows (just count that user as forever gone?).
there are several auth SaaS providers you could look to for inspiration or adoption
tl;dr - clicking a few buttons at prompts is much less effort (and more commonplace) than unam+pword