Check whether policy attached to the role of the provider has an ability to create token. Example
path "auth/token/create" { capabilities = ["update"] }
in the policy attached to the role.