invalidate
Called when the backend rejects the credential with a 401, so a dead token is neither handed out again nor restored on the next launch.
May be invoked concurrently from several subsystems reacting to the same failure; invalidateCredentials serializes those calls, but the implementation must still tolerate being called after it has already cleared itself.