This is very similar to the process with IDCS. When you create an OIC3 instance under domains, you see an application has been created under Oracle Cloud Services. In my case, for my new OIC3 instance called ruck3.
Now I create a Confidential Application - my OAuth app for this ruck3 OIC instance.
The app is configured as follows -
Nothing required here -
OAuth configuration is as follows -
I add the resources from the Oracle Cloud Services app, created for my OIC3 instance -