A pentest of OAuth, SSO, refresh tokens and multiple login paths must test the identity system as one state machine. Map every credential, redirect, token, session, recovery route and fallback. Then test how identity and authorization context change across issuance, use, refresh, revocation, logout, linking and recovery.

Exercising only the primary browser login misses the paths attackers prefer: legacy passwords, mobile flows, invitation links, support resets, token exchange and stale sessions. Coverage should show each path and the transitions between them.

Inventory every authentication entry point

  • Primary SSO and direct username/password login.
  • OAuth or OIDC authorization-code and device flows.
  • Mobile deep links and native-app callbacks.
  • Magic links, invitations and password recovery.
  • Service accounts, API keys and client credentials.
  • Support impersonation, break-glass and legacy endpoints.

Map clients, redirect URIs, identity providers, issuers, audiences and environments. Include old API versions and disabled UI paths that remain callable.

Test authorization request integrity

  • Exact redirect URI validation and unsafe wildcard behaviour.
  • State binding to the initiating browser and transaction.
  • Nonce handling where the protocol and client require it.
  • PKCE enforcement for public clients and downgrade attempts.
  • Response mode, mix-up and issuer confusion conditions.

Use controlled clients and accounts. Confirm the resulting identity and destination, not only whether a callback returns a code.

Validate tokens as security objects

  1. Check issuer, audience, signature algorithm and key selection.
  2. Test expiry, not-before and clock-handling boundaries.
  3. Confirm scopes and claims match the granted identity and tenant.
  4. Try tokens across clients, APIs and environments.
  5. Test malformed, substituted and downgraded token types.
  6. Verify sensitive tokens are not exposed in URLs, logs or storage.

A token accepted by the wrong service or tenant can turn a sound login into an authorization failure. Test each relying party’s validation, not only the identity provider.

Test refresh-token lifecycle

  • Rotation and detection of replayed old refresh tokens.
  • Binding to client, user, session and device where intended.
  • Expiry, inactivity and maximum session lifetime.
  • Revocation after logout, password change, role change and account disablement.
  • Concurrent refresh and race behaviour.
  • Storage and transmission in browser and mobile clients.

Verify issued access tokens after each state change. A revoked refresh token is insufficient if an attacker’s existing access token remains valid beyond the intended risk window.

Test session creation and linking

Confirm that the application binds the returned identity to the correct local account and tenant. Test email changes, duplicate identifiers, account linking, provider migration and users belonging to multiple organizations.

  • SSO account linked to an attacker-controlled local session.
  • Same email from different trusted or untrusted issuers.
  • Invitation accepted under the wrong identity or tenant.
  • Role or tenant claim changed without server-side revalidation.

Challenge fallback and recovery paths

For each primary control, ask which alternate route bypasses it. If SSO enforces MFA, can a local password, recovery link, mobile API or support reset create a weaker session? If a tenant requires federation, can an unmanaged identity still join?

  • Legacy endpoint remains enabled after SSO rollout.
  • Recovery bypasses MFA or federation policy.
  • Invitation flow creates a local password unexpectedly.
  • Support changes email or tenant without equivalent assurance.
  • API token survives account suspension or IdP revocation.

Test logout and revocation end to end

Verify browser session, application session, access token, refresh token, server-side session and IdP session separately. Test local and global logout expectations. Confirm downstream services and background jobs receive revocation or revalidate sensitive actions.

Include authorization after authentication

A valid identity token does not prove correct application authorization. Use peer, role and tenant matrices after each authentication path. Compare claims, mapped roles and resource access across SSO, password, refresh and recovery sessions.

Test operational failure modes

  • Identity provider unavailable or slow.
  • Signing-key rotation and stale caches.
  • Clock drift and expired discovery metadata.
  • Tenant configuration changed during an active session.
  • Partial logout or callback failure.

Fallback should fail safely without silently weakening assurance. Coordinate disruptive cases with the rules of engagement.

Require coverage evidence

The report should list paths, clients, account states, token types, lifecycle transitions and tenant relationships tested. Document blocked flows and production differences. Findings need sanitized requests, claims, state transitions and observed impact.

Use the protocol specifications and current provider guidance as the authority for implementation details, while using the OWASP Web Security Testing Guide to structure adversarial authentication and session testing.

The practical decision

Test the whole identity lifecycle, not one login page. Inventory primary and fallback paths, validate protocol bindings and token acceptance, exercise refresh and revocation, challenge recovery, and repeat authorization checks across roles and tenants. Coverage must show how every route creates and ends identity trust.

Use WIMD for end-to-end identity penetration testing across OAuth, SSO, token lifecycle, recovery and authorization boundaries.