setup security via cooking, auth access to API allowed apps via tokens