GLPI 11 encrypts api/app tokens at rest and decrypts before comparing;
the DB ciphertext never authenticates. Document the working
initSession?user_token+app_token recipe, per-user token minting via
GLPIKey, REST account provisioning, and the singlesignon plugin
callback breakage.
https://projects.knownelement.com/issues/947#note-5519