I have no problem generating new API tokens.

However I find that a client can continue to use a token that should have been revoked.

But the serious problem is I cannot successfully revoke an existing token: