- Validate that the auth token provided has`user` and `gist` scopes only - Validate that the auth token has an expiration time set (a token without an expiration time is considered invalid)