Suddenly our customers, most of who have never heard of certificates before, has to figure out how to order the right kind of certificate, figure out which of the two or three certificates they get in the mail to install in our application, and how to extract the certificate from the password-protected, zipped PDF file in the separate mail. The password for the PDF was of course sent as an SMS...
Then they have to log in to the centralized authorization service and configure the integration access, where including the correct scopes is of course essential. Yet another term our users have never heard of and don't understand. Of course this is all very new, so the setup page has changed several times during the last year, so our guides keep getting outdated.
Secondly the whole token exchange thing is quite opaque. If there's something wrong with the certificate or the returned token, it can be quite difficult to figure out what's wrong from our end.
So far it's been quite the support nightmare. Heck even some of our support folks struggle with how all the pieces fit together and what to do (some have more domain than technical knowledge).
But when it works, it's quite nice.