The same issuer for people, companies, and agents.
Consumer sign-in, enterprise SSO, and machine access tend to be bolted together from different tools, each with its own session model and its own idea of what a token means. Reconciling them is where the bugs live.
- One OIDC provider issuing for end users, federated enterprise users, and agents alike.
- One organization and role model that tokens carry, whatever the login route was.
- One audit log, so a question about access has one place to be answered.