Shaarli rejects tokens whose iat falls outside its clock tolerance, so device/server skew caused HTTP 401 logins even with a correct API secret. Estimate server time from the Date response header, retry a 401 once with a recalibrated token, trim credentials on login, and explain the API-secret vs password mismatch in French error messages. Bump version to 2.14.1 (code 42).