Req: metadata and id_token on OAUTH Token Response

I would not feel comfortable trying to fake support for OpenID Connect by providing an id_token that may or may not be what existing OpenID Connect integrations expect. If we’re going to try and support this use case, we should do it properly.