I thought you were supposed to avoid sessions and states in apps built on top of RESTful APIs. What am I missing?
State happens in the client, requests to the backend come with pre-conditions.
It's an auth session, which is orthogonal (and transparent) to the REST api (e.g with cookies).