The author kinda lost me halfway through. Was mobile or other non-web API interaction ever addressed in any meaningful way? Specifically, how much it sucks to to allow 3rd parties (or even 1st-party non-web-browser clients) access to your API if authentication is done via session cookies? Cuz that's a pretty significant thing to just gloss over.