The idea is to improve discoverability for that use case in extension manager, and allow having the token authenticator without making XWiki an OIDC provider, to reduce the attack surface.