HashiCorp Vault - Deny login access to Root namespace for non-Admin users

The OIDC authorization code flow avoids JWT credentials ever touching the browser, for security reasons.

Turn on the verbose_oidc_logging feature as mentioned in the other topic you posted in (Where can I find the debug logs for OIDC? - #7 by Reggie126) and read it in the Vault logs.