How do we specify secrutiyschemes or credentials for callback url ?
Now that we could pass server b callback url in request. But how do we document or pass the callback url security schemes or defined for that security schemes? some way to specify security credentials like api key during runtime? or do we expect callback urls to be non-protected?