In part 2 of this blog series, Phantom Labs researcher Madhav Nakar explains how Okta Custom Authorization Servers can be abused to modify OAuth and OIDC tokens, and how defenders can prevent attackers from achieving privilege escalation and trusted claim manipulation as a result.