for my understanding the postman screenshot goes towards your application, and the code to Zitadel. What exactly is in the token var in the code? does that include the whole authorization header? including bearer, or only the token itself? we do a split of the bearer prefix which should result in length 2, but in your case it isn't