it is necessary. unless you set a dedicated domain.
also what can fail is if your left access=private.
did you know you can generate a qr code to config your phone from within nextcloud ?
this will also create a dedicated token rather than using your password.