Since you can't use the app management token from client apps for security reasons, Whisk provides an alternative mechanism to support server-less apps. Client application can request short-lived token to access API and keep reference for user.
If you need the token for browser applications, you must provide a list of domains for whitelisting.
The access_token is bound to specific user's id in Whisk Platform and can be used for communication from client app
The anonymous user is deleted automatically after 30 days of inactivity, but if a user makes a request during this period, the validity increases for another 30 days.