Yes because browser implementations do not allow casual DELETE requests. There is a reason the standard says not to use GET for destructive changes.
If I was phishing to get you to click on a link to delete a resource, then I would need to know that token, and if I knew that token, then I could just delete it myself. Note that the HAPI spec discourages the use of cookies (which I agree could allow a phishing attack if you were using cookies as a security mechanism).