correctly use host_browser's hostname as host header for token requests to ensure Issuer is identical