2017-05-19 UTC
# sandro Oh, here's a cool hack: Make the initial bearer token very short lived -- like the code. If you see it used, then you know the receiver implements private webmentions. Remember that. Now, the next time you webmention to that same receiver, you can send a long-lived one. Now you have your long-lived bearer token, but it's never sent to someone who didn't expect it.