I guess they should be able to call them windows.
Can you link to any tool which uses bearer tokens and doesn't grant them through oauth2?
Or it's internal, please explain how the token is obtained.
I haven't seen any to date but I guess I could be wrong