Token revocation is harder than password change

Changing a password is instant. Withdrawing tokens already issued frequently is not.

Many systems issue tokens that are valid until they expire, with no central check on every request, because checking would be slow. So a token stolen this morning may keep working for its full lifetime regardless of what you do to the account. This is why session lifetime matters, and why "we reset their password" is an incomplete answer when an account has been compromised.

More on OAuth and federation