Currently you can only chose between using a cookie or Authorization header for transmitting the token. I would be nice if it supports both.