Engineering teams should audit any internal CLI login flows that piggyback on device code grants—phishing templates targeting help desks spike after UX changes.
Prefer DPOP or mTLS on the token endpoint where clients are non-interactive.
Document downgrade paths: if users cannot complete pairing, support needs scripted flows that do not bypass rate limits.
