Hi Derrick,
Before I try to help with your question, let me suggest that you would get better engagement on this topic if you post to the IAM-specific "IBM Verify" group on this community. Here's a short link
https://ibm.biz/iamcommunity.On your question...
It's not completely clear to me exactly what flow you need to achieve here. You say that ISAM is protecting SAP (which would indicate it would be acting as an OAuth Enforcement Point - validating tokens generated by itself of some 3rd Party OAuth system) but you say you need ISAM to act as an OAuth Authorization Server (indicating that you need it to generate the tokens).
ISAM with the Federation add-on can certainly act as either as OAuth Authorization Server or an Enforcement Point. There's quite a lot of customization possible in both roles.
You also mention that you need ISAM to exchange an Authorization Code for an Access Token. This is a OAuth "Client" activity. The only time ISAM acts as a Client is when it is the Relying Party in an OpenID Connect federation. Our OpenID Connect Relying Party implementation is also very flexible and can be used to implement standard OpenID Connect - or to retrieve an Access Token and then make this available to custom code to perform work with that token before building a session.
So, I think there's a reasonable chance we can help you do what is required but really need to better understand the exact flow before commenting on if it is possible and the degree of customization that might be needed.
Hoping to hear from you on in the IBM Verify group forum.
Jon.
------------------------------
Jon Harry
Consulting IT Security Specialist
IBM
------------------------------