Used mainly for mobile clients to provide some backward compatibility for them to work with access tokens only. Will be removed when mobile adoption rate hits certain percentage
HTTP status code 200 and user model