@axleyjc yup, sender constrained tokens where the client id and client secret is also required in addition to the access token for resource access!