You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
PATs should not be indefinite. I suggest setting a default expiration of max 1 year, and also perhaps creating an option to allow users to set a reduced validity of tokens.
This would likely involve emailing users a courtesy notice of tokens that are about to expire (in, say, 1 week).