Honestly, I think you should have just gone with a more OAuth 2-compliant spec. It looks like you're trying to emulate it, but not really adding anything. I suppose you're skipping out on the authorization code juggling for simplicity?