Currently, all tokens requested in mcp-client
target the same auth server with the same scopes, and, more importantly, an empty resource
parameter (see RFC 8707 Resource Indicators for OAuth 2.0).
Each MCP client should use dedicated tokens, for which we request the correct resource id.