I would really love to know what others are doing, I know there is a concept of creating a token (which I presume will be short lived) so hence the user would authenticate and then would receive a token, this token would then be sent on further calls to the service.