We need to figure out how to phase out shared-secrets based access tokens so they can be dropped in the future. Can we somehow shoe-horn some kind of user notification in here?