Wonder what I am doing wrong.

I am reading the JWT token in C# and all I get is:

According to Choosing an authentication method, I should get a shortLivedToken field.

When you decode the JWT token, you will see a shortLivedToken field. This is an API token that is valid for 1 minute and can be used to authenticate against the monday.com API.

Got it. I had missed the following from Authorization for Integration Recipes

We will not issue a short-lived token if your app’s endpoints do not start with https:// .

