There\'s only thing that server has to do; just check any access token\'s validity.
Clients send to the server user id and access token obtained by FB.getLogin
FB.getLogin
The app token can be found from this url.
https://developers.facebook.com/tools/accesstoken