I see the ESI is using OAuth2 for authorization of the API. Since this uses a browser for SSO (as per best practices of OAuth2) and relies on form posting and redirects to obtain authorization tokens.
How can one authorize a client that has 1) no browser and 2) no UI with OAuth2 authorization flow?
Using a browser and UI is a no go for a service and command line app flow.
Can we obtain a long lived (and revokable) token with or without OAuth2 for such a headless scenario, or API key, and, will CCP be adopting IETF GNAP [1] that addresses such use cases?
[1] draft-ietf-gnap-core-protocol-09 - Grant Negotiation and Authorization Protocol