- Introduced a limit of 200 active refresh tokens per user per application to improve security and performance
- Excess tokens are automatically removed on an older‑first basis, with warnings logged for anomalous flows
- Documentation updated with details on the limit, removal process, and token best practices