After studying for a few days, only the client request header can be verified. How can this be used? Do you have any examples of sessions and tokens?