- Build JWT header and payload manually for exact format control - Use lower-level importKey/sign from Web Crypto API - Use RSASSA-PKCS1-v1_5 algorithm directly (RSA+SHA256 = RS256) - Manual base64url encoding for URL-safe tokens - Add debug logging to trace JWT generation - Avoids SignJWT abstraction that was causing algorithm errors