* set supported endpoint auth method when token_url exists * persist tokens immediately * add token storage validation tests