Oauth usually implies some variability of access - ie selective permissions. Is this more a pure authn layer as opposed to authz?
You have a repo on GitHub... Have you looked at using account public keys for anything? Ie https://github.com/hpsin.keys I hear a lot about how those keys should get used to bootstrap pki systems but I've not seen it happen yet.