Yes, I think that's right. The token endpoint requests cannot be correlated with a user session, so authorization codes would not be either.