It risks more for putting the token in the URL. I suggest reading the token from `Authorization` header. Ref: - https://carsonwah.github.io/http-authentication.html