Good tokens don't work that way. Normally your giving out a 5-10 digit code that is valid for 30 seconds and can be compared with a secure server somewhere. Physical devices plugged into the machine often work the same way, but use a longer code that you don't need to enter. In either case the token never gives up it's private key's.