Should make it possible to specify what is stored in the token + store a session ID rather than a user ID to make the framework more secure.