> C) If you're using OAuth, why not just use the built-in bearer tokens? What built-in tokens are you referring to? AFAIK, they're opaque to OAuth when it describes itself in generic terms. -- Scott