Problem
When you revoke an API token on the Tokens page, it stays in the list for good with a "revoked" badge (tokens.html:31). A revoked token can't be used or restored, so these rows are just clutter, and they bury the tokens that are still live.
Expected behavior
Once a token is revoked, it no longer appears in the API tokens list from the next page load onwards. The revoke action already redirects back to /tokens, so in practice the row disappears straight after you revoke it.
Acceptance criteria
uiPartitionAuthTokens (internal/server/ui_account_pages.go:276) drops API tokens that have RevokedAt set, so they are never rendered.
- The "revoked" badge and the
{{if not .RevokedAt}} guard around the Revoke button in tokens.html are no longer reachable, so remove them.
- When no live tokens are left, the empty state is shown. Its copy still makes sense when tokens have been revoked (e.g. "No active API tokens" rather than "No API tokens yet").
- Revoked tokens stay in
auth_tokens. This only changes the page, not the data: no hard delete.
- Tests: a revoked token is not rendered on the Tokens page, and an unrevoked one still is.
Open questions
- Should expired API tokens be hidden as well? They are just as unusable as revoked ones.
- The MCP/API token listing (
track_list_my_tokens) still returns revoked tokens. Suggest leaving it unchanged, since API callers may want the full history.