Once set, device_token_ack permanently locks out id-only requests (auth.require_device) -- fine for a device that still has its token, but a reprovisioned device has wiped its own token locally and had no way back in short of a manual DB edit. The device's captive portal always redirects the phone to /claim?device_id=... after (re)provisioning, so reopen the handshake window there instead, scoped to a logged-in owner/linked user of that frame.