I suggest implementing an OIDC authentication backend that would deal with [bearer tokens](https://datatracker.ietf.org/doc/html/rfc6750). Should this belong in the main repository, or in a dedicated plugin elsewhere? What do you think?