As the title explains, we want a chance to vet the API Tokens being used in our environment. As such, we want to update the authentication policy to turn off user created tokens. However, we have a service account that all of the admins have access to so that we can create on behalf of others (and thus vet the requests.)
The only option I see in the settings states "Determine whether members can access products with a user API token" Allow or Block.
Any insight into what happens when we choose Block? Does it just go away from the Account Settings / Security page for users? Or does it stop all API Tokens from working?