API with expiring access token

Exactly, but then you have to save the token in the database. Won’t this be a security issue?