Hm, after successful login with OIDC and SAML we currently reply with a 302 (a redirect)
What I have seen work is to use Oauth-Proxy as a means to attach forward auth to OIDC compliant systems.
Other than that we are currently creating a "login api" which can respond with a 200.
@livio what do you think, could we re-use the login api for forward auth scenarios?