Token revocation is harder than password change
Changing a password is instant. Withdrawing tokens already issued frequently is not.
Many systems issue tokens that are valid until they expire, with no central check on every request, because checking would be slow. So a token stolen this morning may keep working for its full lifetime regardless of what you do to the account. This is why session lifetime matters, and why "we reset their password" is an incomplete answer when an account has been compromised.
More on OAuth and federation
- OAuth consent is not proof of identityThe ticket, not the person
- Token scope defines capabilityIt only presses three
- Bearer tokens behave like cashWhoever picks it up
- SSO concentrates convenience and consequenceOne handle, every gate
- Federation shifts where trust livesThe decision moved house
- Redirect URI validation protects token deliveryPosted only where it fits
