GF AuthN specifies separate credentials for client and subject (JWT bearer grant). We currently only have authN of the care organization, which will be the subject in the new GF AuthN protocol. We don't have authN of the client (application of the vendor). We need to find out how to PoC this, and implement it.