The truth about cookies, tokens and APIs Phillipe de Ryck