04 Mar 15, 11:06PM
So it is server-side interface. You need some secured mechanism with open client instead of closing it. Server side generated token with hashed logon information and time expiration isnt enough ? Or you can generate seperated token for each couple of request and response.