We are using AWS Cognito for user pool management, and there is a scenario where when user is unsubscribed we need to invalidate his token. So how can this be achieved, how can