The library uses a flag to disable Cookie handling.
This is a bug: even with a Auth-Token on a request against a protected resource, we still need the cookie there.