Tested it with PEM7 RestApi testsuite and it is working fine :)
The docs for this module say it's based on Flask-Login's session protect mechanism, and was intended to allow session protection in other scenarios. As we are already using Flask-Login, do we need this?