We should add the capability for allowing the client to authenticate using its credentials in the body of the request using POST.