BTW this remark confuses me:
While the access token is a byproduct of the authentication process, it does not prove user identity or authentication.
Isn’t the access token the result of the authn process, proving identity
BTW this remark confuses me:
While the access token is a byproduct of the authentication process, it does not prove user identity or authentication.
Isn’t the access token the result of the authn process, proving identity