The authorization token has an expiry of 5 minutes, we already have checks in place to verify this and throw a Forbidden exception. We need to revoke the token once it's used otherwise it could be used multiple times to gain access to tokens till it expires.