GLPI 11 encrypts api/app tokens at rest and decrypts before comparing; the DB ciphertext never authenticates. Document the working initSession?user_token+app_token recipe, per-user token minting via GLPIKey, REST account provisioning, and the singlesignon plugin callback breakage. https://projects.knownelement.com/issues/947#note-5519