Original vikon_core security.php validates tokens via:
POST db-nica.ru/oauth2/resource/token/introspect
Body: client_id=542&access_token=XXX
Our code was incorrectly using:
GET auth.db-nica.ru/api/profile_applicant/check_access_token
Header: Authorization: Bearer XXX
This was the WRONG endpoint — the profile check is for abitur forms,
not for the update system.