Password reset = fresh start, right?
Wrong. OAuth tokens don't care. They're minted per app and survive a reset completely untouched, still valid, still working, still yours (well, theirs now).
Offboarding kills them. Nothing else does.
Tie your OAuth grants to a personal
00:00

