1. In the case that you are intermediate provider and the call comes in with identity header, can you then juste USE the identity coming in or do you need to reattest. 2. is there somewhere a mini script.cfg which is doing stir/shaken magic with 302 redirect ? wkr,