#ben_thatmustbemefkooman, actually, not storing anything prior to the callback I think is better. If someone wants to use their own site to log directly in, all they have to do is generate a token for themselves (assuming they are their own auth provider)