- isValidIssuer() accepts portfolio-agent, memory-agent, api-gw, etc. - All Authentik providers use same signing key (JWKS valid) - CheckPermissions now checks both 'permissions' (users) and 'roles' (service accounts) - Fixes JWT issuer mismatch for portfolio-agent, memory-agent tokens