Hey John, I have done a fair bit with REST over the years, limited with Aware though. Thought I'd share my thoughts...
In regards to your question 1 - server side paging, to my mind you wouldn't want this. The REST requests should be made and executed and ended server-side, no context no anything kept. Imagine you have a big system with perhaps 10s of thousands (or more) of people/systems utilising your api no way do you want your server being dragged down maintaining contexts for all those connections. Also think about you don't know exactly how client systems will be accessing your API - you need to control what you can control or all sorts of problems can occur.
So, the only option is to maintain paging within the API. Perhaps let the user specify how many records per page - or you define it. Then define the URL/parameters to contain something to identify to your server what page they are asking for.