
kei8v (kei8v) asked a question.
Hi,
If i give a user credential who doesn't belong to a particular application or group, okta is not throwing unauthorized error and making call back request continuously and trying to redirect into application without proper authentication.

Hi Rams,
The behavior of the Okta Authentication API varies depending on the type of your application and your org's security policies such as the Okta Sign-On Policy, MFA Enrollment Policy, or Password Policy.
Please refer to the below documentation: https://developer.okta.com/docs/reference/api/authn/