Links the token with the web session ID of the servlet container. If the user disconnects and reconnects, the previous tokens will not be valid any longer.
It's recommended to keep it enabled for security reason.