The authentication code must be generated from two or more elements categorised as knowledge, possession and inherence, with breach of one element not compromising the reliability of the others, and the code itself being non reusable.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.