thanks, both are useful.
1. we support OAuth apps today, and we're growing the catalog based on demand. we support rotating and refreshing tokens for those.
2. I'd like to understand your case better. sitting in the request path means we could own retry mechanisms, but I'm curious what made you think of it, what kind of use cases did you have in mind?