points
OAuth/OIDC is a problem if you're trying to shove a bot-shaped peg into a browser-shaped hole, but we don't need a new protocol to solve that.
If my security system is showing friction when there's a wave of agentic slop, I'd say that's a win.