Right now, I have a web app, where a user can sign in, receive a token and then access resources with this token. In the token, there is its userId. Every time I receive the