If you’ve ever searched for OAuth (or OAuth2 or OpenID connect/OIDC), you’ve probably been greeted with a picture that looks like this:
along with some descriptions of resource servers, the difference between authentication and authorization, consent screens, token endpoints, and more.
And while that can be helpful,