Hi, crhym3
It seems that simpleauth supports using client_id / client_secret in the request-body for client authentication.
Howerver, OAuth 2.0 protocol says,
http://tools.ietf.org/html/rfc6749#section-2.3.1
Including the client credentials in the request-body using the two
parameters is NOT RECOMMENDED and SHOULD be limited to clients unable
to directly utilize the HTTP Basic authentication scheme (or other
password-based HTTP authentication schemes)
Please support the HTTP Basic authentication scheme for client authentication, especailly at token endpoint