Hot take: all ActivityPub servers that make use of OAuth2 must expose that info in their Actor response bodies. Dramatically simplifies the act of getting a token when coupled with OAuth Server Metadata implemented as well. If Mastodon (and other popular services) have done this, it could have made the act of implementing clients implementation-independent (because you have to figure out authentication as part of the development process).

