Deactivating a user should shut off their API tokens too
When someone leaves, an admin marks their account deactivated and the login page starts rejecting them. Their personal API tokens often keep working anyway. The token middleware looks up the token has
authbyexample.hashnode.dev1 min read