This is the result of a conversation @gRegorLove and I had at IWC SD 2023 today.
In my implementation, I take the me property of the access token response and use this as the user identifier.
@gRegorLove pointed out this idea is not explicit in the specification. It is implied by the fact that the 'me' entered into the client need not be the same URL output as the 'me' parameter, however, which was my assumption.
Proposing that this be noted more explicitly in the specification.