If the domain is protected, like on stage domains with a basic auth, it does need additional server config, to make it work. One way could be a static url prefix which can be opened on the server by default, or just something /.well-known/synco-token