While we're talking about authentication: Once the user is logged in, how practical is it for native apps on Apple platforms to use something more secure than bearer tokens to authenticate with the service on each request? I'm reminded of https://mjg59.dreamwidth.org/59704.html