OTK : How to secure API?

I have just setup OTK 3.0 and can access oauth/manager and /oauth/v2/client/authcode .  I have created new client key and  now try to use in my API policy.  I have drop fragment OTK require 2.0 and try to pass access_token thru query parameter.  But it is not working.  Need Help.   Sample Policy and soap call.  Any other documentation which can help me to use other OTK fragment?