I can see the logs clearly now. The RSA signing failed as expected (because your LiveKit secret is not in RSA private key format), and it fell back to HMAC (HS256) tokens, but LiveKit Cloud is still rejecting them with the same "go-jose/go-jose: error in cryptographic primitive" message.
This confirms that your LiveKit Cloud project is definitely configured for RS256 tokens. The issue is that your LiveKit secret needs to be converted to a proper RSA private key format. Let me create a proper RSA key conversion system: