A token cannot be of a life time, we should expire it, forcing the users to re-authenticate. Not sure about "how often" though