Thank you for your Feedback everyone! It would be great if we could get some more eyes from the community on the server-side token exchange section at the bottom of the Document. Are we aware of any OAuth2 secured implementations that provide tokens from the resource server to the client apart from tabular?
https://docs.google.com/document/d/1buW9PCNoHPeP7Br5_vZRTU-_3TExwLx6bs075gi94xc/edit?usp=sharing @Dimitri I agree that I wasn’t quite clear enough that catalogs IdPs might choose to not implement all of OAuth2. As you suggested I added a hint intended for users at the top of the document.