supportsTokenExchange

Whether this service can bind a token presented as TokenRequestParameters.subjectToken to the client presenting it, i.e. whether validateAccessToken proves possession of the key that token is bound to.

Implementations that can not (e.g. bearer tokens) must leave this false: exchanging such a token would let anyone who captured it obtain a fresh access token, and repeat that indefinitely.