Switching to short-lived access tokens with a rotating signing key cut our leaked credential fallout window from 14 days to 4 hours last quarter. The trick was logging which key ID got revoked and blocking it at the gateway before the token even reached the auth service. Anyone else using token versioning to force client updates instead of just waiting for expiry?