if your APIs will be consumed both ways, then you ...
# general
r
if your APIs will be consumed both ways, then you can even support both methods (cookies XOR auth headers)