Create an access token and respond with its key/secret/context.
If the consumer is not registered, the given token key doesn't exist
(or is not associated with the consumer), the signature does not match
or no permission has been granted by the user, respond with a 401.