The (paper) token should be exchanged for a JWT or something similar. This prevents issues where the paper tokens are lost or leaked. This does also prevent users from logging in with multiple devices but that's acceptable.
The (paper) token should be exchanged for a JWT or something similar. This prevents issues where the paper tokens are lost or leaked.
This does also prevent users from logging in with multiple devices but that's acceptable.