From a security perspective, it is needed that a new token could be generated for an 'External start' and also old ones could be revoked.
Example: When someone leaves the company and (s)he knows the url/token and could possible abuse this.
Even better would be if there could be multiple tokens (read: customers) per 'External start' url and if in the workflow designer, the used token could be retrieved/used.