3 ms·
>In this case the requesting party will have a token to prove their identity, and can forward it to the third (or 4th … nth) service without needing to incur a
by sascha_sl 4y ago
>In this case the requesting party will have a token to prove their identity, and can forward it to the third (or 4th … nth) service without needing to incur a real-time validation each and every time.
Someone missed the entire point of audience claims in OIDC - on okta.com no less.