Open
Description
Users should be provided an API to list and revoke active API access tokens for their account and any web console sessions they have open.
Ideally users could also see metadata associated with each of type of these active access method, including a unique identifier, when they were last used, and the IP address they were used from.
This issue is user counterpart to #3892.