Whoever told you that the tokens are sent as clear text?

The authentication token is not sent from the handset but from the server to the handset.