-- Reverses 000014. -- -- Drops every access and refresh token, disconnecting every connected MCP -- client. Users reconnect through the normal authorization flow. -- -- This destroys no application data: every row is a credential. Cookie sessions -- are in `sessions` and are untouched, so the merchant-facing product and the -- existing console keep working exactly as before. -- -- No touch to oauth_clients or oauth_grants, which 000012 and 000013 own. SET search_path = public; DROP TABLE IF EXISTS public.oauth_tokens;