This thread is almost 2 years old and this is moot now, because you can generate several valid tokens for the same application/user now.
And I’d rather keep sensitive data like access tokens completely clientside. If I store it in a central database I have to make sure the tokens of potentially thousands of users are safe. I don’t even want to have access to any sort of login data or my users.