Platform API 403 Forbidden during load test security audit

403 Forbidden on /api/v2/authorizedapps/me

Running a security compliance check with JMeter 5.6.2 from Singapore. The app works fine with 1 thread but fails under load.

  1. Generate OAuth token for the app.
  2. Ramp to 50 threads hitting the endpoint.
  3. All requests return 403 after 10 seconds.

Is this a rate limit or a scope issue? Need to pass the audit.