and to asheesh's point about static publishing (not sure if it's even in the context of un-authed responses): token-based static responses would be not-so-static I guess