We are very close to an implementation of the OpenID Connect “Basic Client Profile”. This is the “OAuth2 sign-in” feature in IdentityServer that most people want – just done right. In addition we have AuthorizationServer which features a full implementation of OAuth2.
That means that the plain OAuth2 endpoints in IdentityServer are not really needed anymore. Rather use IdentityServer for IdP/authentication/identity token concerns and AuthorizationServer for R-STS/authorization/access token concerns.
That further means that we will remove the OAuth2 endpoints (apart from resource owner flow which is close enough to WS-Trust) from IdSrv in one of the next releases.
If you have concerns or feedback, please leave a comment.