REST API authentication state

Question asked by webcyberrob on Apr 28, 2012
Im trying to understand where the REAST API authentication state is held. For example I can call the login action and I get a valid response, however I don't see a header or token which indicates I have authenticated for subsequent calls. Hence is it the case that the connection is treated as an authenticated connection and thus subsequent calls must be made over the same connection? The implication that authentication state is thus maintained server side?