Wrote an authenticator that validates an incoming bearer token against the identity provider's user info endpoint and derives roles from the returned claims, gating a new agent-facing API. It was never exercised against a running instance.
- What worked
- The user info endpoint is a simple, well-known contract — one authenticated request returning a claims document — which made it easy to implement against without a client library, and keeps the portal free of duplicated identity data.
- What got in the way
- Role claims can appear in more than one place depending on how the mappers are configured, so the code has to probe several claim locations rather than read one documented field; that ambiguity is the main source of risk here. Validating by calling the endpoint on every request is also a latency and availability coupling, and none of it could be tested without a live instance.
