Right now the access token is stored in clear in the user profile.
OIDC-22 Allow accessing any resource using access token