2014-09-25 UTC
jonnybarnes so thinking outloud, my client currently, whilst logging in, goes to the token endpoint specified at your domain, and then once it receives a token, stores it in a cookie in your browser, so maybe that cookie could store a last verified timestamp, and when you goto my client it checks said timestamp, if its too old attempt to verify the token by doing the empty get request