The recent changes of the API

Sure you can do oAuth via a server running on Localhost

Token is for implicit auth

An example