Verification token rotation

Goal

A token which is simple and stored "forever" is not secure. How can we improve without a lot of effort? What are the best practices in this situation?

TODO / How to implement

Acceptance criteria