now that https can guarantee the security of passing api parameters, it is not necessary to sign the parameters, only userid is needed for identity verification, and there is no need to generate a new access token to bind to the account at the backend.