Hi Jarrett,
Any documentation available will be in the product docs. I'm not sure how much it says about sessions though.
There are a number of places where the concept of a "session" might apply in OIDC.
If ISAM is your OP, there will be a web session there when the user authenticates to access the /authorize endpoint.
If ISAM is your RP, there will be a web session there which is created when the incoming JWT is processed and exchanged for a SAM Credential.
A client might also use the Access/Refresh token acquired during SSO to make further API calls to endpoints protected by OP Access Manager (really this is now OAuth but closely related). A session can be created at WebSEAL for the OAuth client in this case - for performance.
Could you describe a little more about what you want to know?
Cheers... Jon.
------------------------------
Jon Harry
Consulting IT Security Specialist
IBM
------------------------------