I’ll take a look - unless recently deleted, they are existent.
However, I don’t think the api provides a great way to let us know which users may have revoked their access. Unless I’m missing something.
We do remove them when we discover they are bad, but proactively searching them out is problematic. We can probably come up with a test script to weed out any bad tokens if that is now required.