Maybe I am misunderstanding, but how is it possible to encrypt the access token? Doesn't the server need it in plaintext to make requests?
With a system of this scale, the web server will probably be making no API calls, as everything might be sent via some distributed system.
There are, anyway, many solutions to store the keys, a key vault that is separate from both database and application/web servers would be ideal.
There's not much to do if an attacker gains control of every machine, so the general idea is to keep every attack vector as isolated as possible.