Private-key signing of access tokens support would be nice, to support DPoP.
Although still in draft, there's already a Java based implementation in Nimbus, which should be license-compatible.