Hi,
I'm doing some small reading, and noticed that the client doesn't actually send a user-agent with (except for "superagent-version" which doesn't help LE or others) and did some quick (unverified) napkin code as a PoC which I will most likely forget to mention, so just to point it out there and put it in the open...
https://community.letsencrypt.org/t/acme-v2-draft-13-compliant-key-rollover/68953
https://tools.ietf.org/html/draft-ietf-acme-acme-13#section-7.3.6
https://tools.ietf.org/html/rfc7231#section-5.5.3
serveroffline#1
My thanks to Peter Waher for warning me about the key-rollover that triggered it...