5.3.21
The authorization endpoint has moved out of /wp-json and into wp-admin. A REST request does not accept a cookie as proof of anything without a nonce, so a browser arriving from a connector read as logged out however long its owner had been sitting in wp-admin — and was sent to log in again, every time.