2018-01-15 UTC
# aaronpk anyway the main point is: for logging in to wordpress, the plugin should be a normal IndieAuth client, which discovers the user's authorization endpoint and checks the code there, no access tokens involved. when you go to add the indieauth server part to the plugin, then the plugin will be issuing its own tokens.