A token the OIDC directory rejects is an authentication failure, so it counts toward the ban; a network, provider or configuration fault stays an error and doesn't. Before, a rejected token was an error too, so bad tokens never led to a ban. The Keycloak container now imports a second realm, so test 10 checks /api/discover and the PACC record answer with each domain's own provider. Test 18 checks that eight sign-ins during an outage don't ban the client, while bad tokens do.