I would think you'd want to expire the tokens just to keep your database small. I see that as a potential denial of service angle if some a-hole wanted to cause 10C trouble.
//