For the operator of an app, they should be able to verify this using the API. This way permissions of a user who didn't log in to the target application using an API key can still be checked (e.g. for data stories where users will sign in using Satosa)
For the operator of an app, they should be able to verify this using the API. This way permissions of a user who didn't log in to the target application using an API key can still be checked (e.g. for data stories where users will sign in using Satosa)