How is it enforced on the server side? I see no documentation regarding that. The only thing that is written down is that you get a superficial token and use that service as a front for accessing a public website. Again, am I missing something?