When receiving an access token from SIWA, is it ok ie best practice to save this token in a database for invalidating at a later stage?

Viewed 16

I'm coding invalidating the SIWA access token when a user deletes their account and user data.

The coder who originally coded my SIWA code only saved the access token in session when a user logs in with SIWA. Is it safe for me to also save this access token in the user's account so that I can retrieve it later to invalidate it if they decide to delete their account and user data?

Thank you for your time and help.

0 Answers
Related