I get the feeling that this seems to be a common issue with any authentication or authorization "standard" nowadays. When I had to implement SASL OUATHBEARER support, and I started poking around how to actually implement OAuth2 from the standard itself, it was similarly full of "here's several ways that you might do something, and whether or not they're supported by the provider is implementation-defined, and what you have to provide with the requests is implementation-defined, and where you go to find the stuff is implementation-defined."
And frustratingly for me--trying to implement this in the course of a SASL method as a client--there's not even anything hooked up in SASL that might have hinted at the client what to do. Which is insane because the entire point of SASL is to bridge the gap of "how to request authorization given username, hostname, protocol." It makes me want to retreat back into Kerberos as a better way of supporting SSO than anything invented in the decades after it.