OAuth 2.0 Token Exchange lets a client hand the authorization server a token it already holds and get back a different token — narrower scope, different audience, and optionally a record of who is ...