For situations where admins add users.
Require 'openid' in scope for all requests. Require 'offline_access' for returning refresh token.