Invalidating Tokens that users post

Are there any rules or restrictions against using Discourses native API here on the developer forums?

I see a lot of users who accidentally post their access tokens in their posts, and get warned by other users that they should invalidate them. It’d be a fun little side project to occasionally scan for new posts using the built in API and invalidating them with Twitchs API to prevent malicious activity.

Gotta stay safe out there :sunglasses:

