Also be wary when using apps and especially when enabling push notifications. Lemmy API currently lacks any kind of support for partial access to an account (unless this has changed recently). So, apps cannot, for example, get read only access to your account's inbox. Apps can get either no access or full access. When you sign up for push notifications, an authentication token is stored to the push notification server which gives full access to your account to who ever happens to get their hand on that token. If there, for example, happens to be a security vulnerability on the push notification server, it might leak those tokens.
If you have enabled push notifications on some Lemmy app, and want to invalidate the token, you can just change your password.
Here's a post by Memmy for Lemmy's developer about push notifications: https://lemmy.ml/post/1534493