Why does the length matter compared to when they are sent with cookies or with a special header?
Or many usually have separate domain/subdomain names for API and static content in the first place.
I think having a separate prefix/subdomain would be generally good practice for defining scope which should be authed as well.