Logto returns opaque access tokens unless the resource parameter is included in both the authorization request AND the token exchange. Append resource to the token endpoint POST body per RFC 8707 so Logto returns a JWT access token with Custom JWT claims. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>