Secure-by-default reactive OAuth2 resource server: JWT (and opaque) validation, claim-to-authority mapping, default-deny chain and hardened security headers. Delivered to applications via the application starter.