A reminder to validate access tokens when using OAuth2

Hi all! Back from Devcom. I’ve summed up your feedback, questions, and concerns so far on this thread and have inquired with the security people to make sure we get accurate responses.