I included that section precisely for this reason, and it’s definitely a viable technique to serve the token in a message from the Channel itself. This doesn’t work for all cases, though. My token service is separate from the Channel service, so I have the client request the token from the token service every 5-9 minutes (10 minute lifetime).
The objective here is to decrease exposure, not remove it completely. There’s a big difference in looking at a log from 30 days ago and accessing the system, or looking at one from 5 minutes ago and accessing the system.






















