TokenProvider
Supplies a Cognito access token for the X-Authorization header.
Deliberately one method with no notion of how a token is obtained. On a backend that is a client-credentials exchange; in an untrusted client it is a call to a service you control that performs the exchange for you. The SDK does not need to know which, and keeping it out of this interface is what lets an Android app hold no client secret.