Replying to @nu4ur
Usually you'll create a new set of client credentials that represents the resource server, since the OAuth client shouldn't be introspecting tokens. There isn't really any other form of authentication for the API so it's kind of an overloading of the term "client credentials"

Nov 24, 2020 · 8:38 PM UTC

1