2014-04-29 UTC
# kbs the rfcs are confusing aaronpk :) http://tools.ietf.org/html/rfc6749#section-3 says "token endpoint - exchanges authorization grant for access grant" - which is how I read your diagram as well. http://tools.ietf.org/html/rfc6750#section-1.3 has the "authorization server" host the "token endpoint"