2022-05-16 UTC
# gRegor I'm working on IndieAuth token introspection and wondering best way to add authorization, since it's a MUST in the spec. https://www.rfc-editor.org/rfc/rfc7662#section-2.1 gives an example "using a separate OAuth 2 access token" but I'm not sure how clients would get that separate token?