@evan there doesn't seem to be anything in rfc8414 that prevents a redirect to a different auth server.
I suppose the response could also be hardcoded remote urls for `registration_endpoint`, `authorization_endpoint` and `token_endpoint`
ditto for the actor.endpoints
@evan it seems like the `issuer` field of rfc8414 and the `iss` field of rfc9207 are for this type of use-case