That's an interesting idea... instead of storing the bearer tokens associated with your internally-pointing ocaps (held by external users), salt and hash them. That way if your server is compromised the ocaps that other people hold to you internally can still be valid.
https://groups.google.com/d/msg/cap-talk/zGu5th2Lsxc/84PZ5TD2CwAJ
 
      Christine Lemmer-Webber
Christine Lemmer-Webber All Bobinas P4G content and data are available under the
 All Bobinas P4G content and data are available under the