#ZegnatAt that point you may as well also ignore the expiry times that are a MUST for assertions and suddenly you are mostly (completely?) back to what AutoAuth already describes. Because the assertion may as well be a random token now, it doesn’t need to contain any accessible information.