https://medium.com/@haroldfinch01/how-does-oauth-2-protect-against-things-like-replay-attacks-using-the-security-token-c25f64088d50