The getUsersHavingSuperUserAccess() method was updated in #15410 and token_auth was removed from the return array, but its annotation was not altered.
Since no sensitive information is returned any more I believe it's enough to remove the note instead of updating it.
None of the above points apply.