Hi @jsw,
I went ahead and moved your reply to its own topic with a reference to the original topic for better visibility for your question.
I see that you are specifying an audience. Is the audience your own custom API? If so, is it configured to allow offline access?
Also, within your SPA’s application settings, do you have Refresh Token rotation enabled?