Is tying session tokens to IPs actually common? I can't imagine it is given the unreliability of IP addresses causing issues.
I used to live somewhere where outbound traffic went through one of three CGNAT IPs at random, and I only had auth issues with one really old site that predates the NAT hell that is the modern internet.