alternatively the pds could generate some state that only the client needs to know and shove it in the fragment part of the uri on post-oauth redirection. then you make your requests with the token + the server's assertion that the client secret is known + the client-only state
add a skeleton here at some point
5 months ago