can you double check your sub and iss, it should be the api key not the application id
in portal
Security details
Active API keys - and then
Active keys
Key
to rule out code issues I would firstly create the jwt via something like this
and then run your tests against int environment in postman