If I can summarize:

Reverse tokenizing will not be supported because tokenizing is a method of security that we shouldnt be using in the first place?

I see an easy fix that makes both side happy. A flag used when tokenizing. Omit the flag and the script can be extracted, add the flag and the application wont let you.