What prevents REST based service clients to share the STS issued token with each other?
Bearer token are like passwords and can be shared or replayed.
Codeplex Link