Decides who a SCIM request is and whether it may proceed, synchronously.
A credential presented and failed is always a refusal; one that worked is used; only then does "is a credential required" decide a request carrying none.
the request
Optional
read, write or none (discovery; the default)
read
write
none
the decision: { ok, status, ... }
{ ok, status, ... }
Decides who a SCIM request is and whether it may proceed, synchronously.
A credential presented and failed is always a refusal; one that worked is used; only then does "is a credential required" decide a request carrying none.