A JWT signing failure was silently ignored, leaving the user on the setup page with no auth cookie and no explanation for subsequent 401s. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>