Identity and session paths
We test login, token issue and refresh, logout, password reset, MFA, API keys, OAuth/OIDC flows and service-to-service credentials. The objective is to determine whether a lower-trust identity can obtain or retain access beyond its intended role.