I think it should be a database so that we can persist it to disc. I also think that it should be possible to specify it in the auth-scheme declaration.