carrvoIt is common to introspect during every resource retrieval. My endpoints serve as both a client and a resource. A gotcha is that mod_oauth2 requires the `sub` claim to properly update Apache's user field for it to be passed to the authorization layer.