A year ago we implemented OAuth for 100 popular APIs.
Our experience was exactly like OP describes: https://www.nango.dev/blog/why-is-oauth-still-hard
Our experience was exactly like OP describes: https://www.nango.dev/blog/why-is-oauth-still-hard
“… one of the principle issues is that it's less a protocol and more a skeleton of a protocol.”
If you have an example of where that's not the case, I would also love to hear as I work in this area (perhaps you're thinking about how OAuth does not specify at all how authentication happen? But that was a good call, OAuth 1 did and it was too limiting... also OpenID Connect is pretty widely adopted now, and it fills that gap well).
Source- done over 300 system connections. Save the straight API keys, they're all special and unique snowflakes.