If the OpenID sign algorithm is set to for example `HS256` and a user tries to login "using a organisation account" the following error will return: <img width="937" height="99" alt="Image" src="https://github.com/user-attachments/assets/0c9068cc-f067-4e4c-8f0c-e898e425f36e" /> Ideally the algorithm should be validated when saving the OIDC client.