Is this an OAuth server?

No, and you probably already have one. OAuth answers whether a client may call an API. This answers whether the party behind that call was authorised, by whom, and within what limits — a question that only becomes interesting once the caller is an agent acting for someone else.

The artifact that settles it
/spec/standards · tracks RFC 8693
↑ delegated authority→ the definition lens · gda.group↓ the verifier