Edge BYOC config failing with 401 after zendesk move

Just noticed that our edge connectivity keeps dropping every 15 mins. we are moving from zendesk talk to genesys cloud using a bring your own cloud setup on aws. the edge cluster is in eu-west-1 but the agents are in france. when we try to register the edge to the public cloud tenant it throws a 401 unauthorized error on the /api/v2/edge/registration endpoint. i checked the credentials and they look fine. same keys work for our prod tenant. is there a specific permission set for edge admins that i missed? in zendesk we just added users to the support role and it worked. here i feel like i am missing something basic with the byoc handshake. the logs show ‘token validation failed’ but the token is fresh. any ideas? i am stuck on this for 2 days and the migration deadline is next week. please help.