[x] ~Switch to using newer Duende Identity Server~ Not gonna do it. Just using ASP.NET Identity / APIs for authentication interactions (e.g. login, etc.) and Microsoft's custom opaque access tokens rather than JWTs.
[x] Also consider not using flag for PostgreSQL 9.6 compatibility