I added "implement oauth2 support" to the todo list from that comment. Shouldn't be too hard. If anyone has tips for simple-to-setup-oauth2 setups to test against, let me know. Is oauth2 support enough to get SSO covered? SASL (as used by SMTP/submission and IMAP) supports other methods (openid, saml), but I don't know clients that support that.