It seems a number of auth API's require both a token and tokenId. There doesn't seem to be any reason for this and it does make the API look more complicated than it has to. It would be nice if we could simplify to just using a token.