Original vikon_core security.php validates tokens via: POST db-nica.ru/oauth2/resource/token/introspect Body: client_id=542&access_token=XXX Our code was incorrectly using: GET auth.db-nica.ru/api/profile_applicant/check_access_token Header: Authorization: Bearer XXX This was the WRONG endpoint — the profile check is for abitur forms, not for the update system.