The API-based password management mechanism is still undergoing design study. It is expected to operate via an API gateway-to-API gateway model and may support machine-to-machine password changes, with further security and implementation details to be shared once the design is finalized. In addition, the login process will incorporate an API-based token retrieval mechanism, whereby participants will obtain a token via API and use that token as the password when connecting to the gateway.