I say to the streamer “click this link and then hit accept”
"this link’ is a link to my website/tool, that redirects to Twitch, they hit accept.
They come back with a ?code which is exchanged for an access and refresh token.
Theres nothing simpler than that, as that is how oAuth works.
Not sure what you mean here.
A generated auth token has a client ID attached to it.
And both need to be specified when you call the API.