Flow 1
401 → metadata → AS → token
- 1
Client calls the API, gets 401 with resource_metadata URL.
- 2
Fetches PRM. Records resource and authorization_servers.
- 3
Fetches AS metadata (8414 and/or OIDC). Verifies issuer.
- 4
Performs OAuth 2.1 with resource=canonical URI. Presents the token only to this RS.