Points: - Authorization is via cookie - Posting can be done via POST with correct json (Sniff response formats via dev tools)
Points: