We could decide to check the user's required authentication methods and auto-remove token-client-registration if it is present. This would require checking this on every site load -- so we might want to just go with the feature we have that only checks it and auto-removes it during login instead.