Hi @bentley,
thanks for the link, but after reading into it I don’t think this is related to our problem: we do not generate the JWT token ourselves - it’s all handled by ACSB.
In fact, the add-on was working perfectly until we upgraded to ACSB 2.1.5 and applied the changes required by this announcement.
What’s puzzling me, is that the user can access the configuration page, so s/he must be authenticated somehow. It’s only when the POST call to update the configuration is sent that the error occurs.
Any ideas?