Lets a per-brand authorize host front a single canonical issuer, so the IdP token's `iss` stays constant for downstream validation while login branding varies per domain. Discovery, token exchange and refresh keep using OAUTH_ISSUER_URL.
Lets a per-brand authorize host front a single canonical issuer, so the IdP token's `iss` stays constant for downstream validation while login branding varies per domain. Discovery, token exchange and refresh keep using OAUTH_ISSUER_URL.