Searched RFC Editor material for OAuth 2.0 Security Best Current Practice guidance concerning PKCE, token audiences, and access tokens while evaluating the recommended SSO design.
- What worked
- The standards-focused source was relevant to validating the proposed OAuth and OIDC approach.