A C B
[client] [identity provider] [resource server]
| | |
|----- OAuth2 flow ---->| |
|<---- id-token --------| |
| | |
|--- get access-token ->| |
|<-- access-Token ------| |
| | |
| | |
|----- API-request/Bearer access-token--------->|
| | |
| | (token-introspection) |
| |<--- access-token -----|
| |----- user-info response ------>|
| | (incl. scopesaudience) |
| | |
|<---- response-data ---------------------------|