Restrict lifetime of access tokens

This refers to issue:

The references in oauth-security-topics didn’t really line up - so I left them out.

The closest recommendation I could find was in: https://tools.ietf.org/html/rfc6819#section-3.1.2 - which I suppose we could reference?

10 mins is arbitrary…. up for discussion.

