Design question: User/password/access token/OAuth client handling?

Yes, I got that, but that doesn’t appear to be the case for every token - there’s an extended discussion about that over here.