https://blog.mojeek.com/2020/12/frequently-asked-questions-a...
"Search engine companies typically earn revenue from advertising (in many different forms). Other sources of revenue can include APIs and partnerships, including site and enterprise search. Recently search companies have started to explore a subscription model and/or micropayments. At Mojeek we are exploring options for our business model and all of these are potential routes for us; indeed we have had small revenues from some of them without being focussed on revenue streams. In 2021 we will start to focus on which revenue options to pursue proactively. Enabling people to search on Mojeek without tracking (aka surveillance) is a something we will not compromise on, so any routes we go down will be guided by our privacy-by-design principles."
Mojeek generates a signed token that IS authorization, you match it against a list of valid tokens, with no other information required.
This could be used to federate subscriptions, and hosting of front ends such that they could stand alone without having any knowledge of the users, while only serving valid users.
Flickr has something like this that grants access to an otherwise private portfolio, yet the user can revoke it if necessary, without ever sharing passwords, usernames, etc.
[Edit] - Example: On a linux machine, how could you give access to only one file in the whole system? Answer: By setting the permissions on every single file other than the one in question to deny access. Set the permission to allow access on the one file you care to share.
With Capabilities, the token IS the permission... and it doesn't really take much to implement it, once you completely grok the idea.