Expiring offline access tokens required for new public apps starting April 1

Good! I’m glad you’re focusing on hardening merchant access. This helps automate best security practices.

In the same vein, please consider separating financially risker mutations into their own scope, separate from write_orders:

[Proposal] `orders_write_transactions` scope