@trwnhinfinite love β΄³ "oauth i think HTTP auth-schemes for WWW-Authenticate and Authorization headers are a good idea to signal which ways of auth are supported. profiling oauth is one step; advertising it as an auth-scheme is a good way to remove ambiguity"
Yes, if you make a request to a resource server and it's unauthenticated respond with WWW-Authenticate.
But you probably don't want to use Basic auth with a decentralized network of applications because then all the applications know your full password..