Keep 'token' in the session since there are hardcoded references to this