401 after refresh despite valid expiry

Clock skew hitting us again. Refreshing the token works fine, but the subsequent request to get a user summary returns 401. The expiry is 350 seconds out, so it’s not a time issue on the token itself. Any idea why the platform rejects a token that’s clearly valid?