OptionalaccessOptionalaudienceOptionalauthOptionalauthOptionalauthtool or adk can generate the authUri with the state info thus client can verify the state
OptionalclientOptionalclientOptionalcodeThe PKCE code challenge method. Only 'S256' is supported; any other value is rejected when the authorization URI is generated.
OptionalcodeOptionalexpiresOptionalexpiresOptionalidOptionalnonceOptionalredirecttool or adk can decide the redirect_uri if they don't want client to decide
OptionalrefreshOptionalstateOptionaltoken
Represents credential value and its metadata for a OAuth2 credential.