> it was purely server-to-server access, but for some reason wrapped in OAuth... because... architects and compliance something something]
That sometimes feels like the bane of my existence. Everything has to be OAuth and use refresh tokens, certificates etc. when I never care or use any user data. No one logs in. This is all our server talking to their server. Revokable Bearer Tokens used to be used, but every API that updates switched to OAuth which makes everything more complicated.