Difference Between API and APP and Associated Login Methods

Hi @john.gateley ,
I had the same question as Shaun, so thanks for the answer.
However I also want my services to be stateless, so I don’t want to use session cookies.
In that case I suppose the expectation would be for the client to keep sending the accessToken with each request - is that correct?
Thanks,
Manjuka