Github already has system to invalidate tokens without storing any hashes themselves https://docs.github.com/en/code-security/secret-scanning/sec...
I'm thinking of a generic approach which is independent of where you got the secret key and its format.