web auth flow TODO(naphat) we should make this only available to our UI appget https://example.com/v1/auth/get_token