I'm coding invalidating the SIWA access token when a user deletes their account and user data.
The coder who originally coded my SIWA code only saved the access token in session when a user logs in with SIWA. Is it safe for me to also save this access token in the user's account so that I can retrieve it later to invalidate it if they decide to delete their account and user data?
Thank you for your time and help.