"Authorization" header value is cached by the browser, and then is sent alongside every request to that domain. It means that it can be used for tracking purposes just like cookies.
Once you've developed this feature, make sure you make sure to enable it by default