Remember encryption is not the same as hashing :) With encryption you can reverse the process, as long as you have the encryption key(s). With hashing, you can't.
I realize, but whatever server is making the API calls needs unrestricted access to the key and the encrypted tokens. So if server is compromised, the access tokens are necessarily compromised too, aren't they?