So long as we're able to get a strong static secret value from users, password or otherwise, that's all that matters. When we first looked into alternative auth mechanisms, it appeared that they did not provide us a value like that, but will definitely be looking further into webauth to explore this possibility some more, thanks for the tip