401 on every call | aud and iss differ, carry a path (/v2, /v3), or name another environment's host | Set both to the base URL you call, with no path |
401 on every call | iat/exp in milliseconds, or exp already passed | Use Unix seconds; mint a fresh short-lived token |
401 on every call | Signed with the wrong key or algorithm, or kid names a different key | Sign with the key issued for this environment; put its id in kid |
404 on every call | kid in the header does not equal the sub claim | Send your key id in both |
401 on /v3 only, /v2 works | v3 is not enabled for your organisation | Ask us to enable v3 |
401 with no token checks at all | Authorization header missing or not Bearer <token> | Send Authorization: Bearer <token> |