`OAuth2ClientAuthenticationToken` should support any type of credentials, e.g. `client-secret`, `Jwt`, `X509Certificate`, etc.