- Bearer token in Authorization header (KOReader, API clients) - URL path parameter (Kobo sync: /api/sync/kobo/:token/...) - Query parameter (OPDS: ?token=...) - Update Kobo sync routes to use token in path - Add authentication method documentation to OPDS routes