Details of the approached for authorising API access.

TODO: Complete this. Reference patterns, local (TOM), future (Strat Auth). Introduce claims and tokens.

Tags: design