Remove and reupload was not successful (had actually tried that previously) never have seen a save button with regard to the profile avatar . Hard clear and reload of cache was also not effective. I tried the cache clear and reload at each of the following locations: profile page, dev server campaign listings (home), campaign details page, and within the campaign. There was no change in the avatar. The uploaded avatar continues to work in all locations except the Dev Server. While the developers tools window was open I noticed the following errors and warnings listed within the campaign: Error 1) Refused to execute inline script because it violates the following Content Security Policy directive: "script-src 'self' 'unsafe-eval' https://*.googlesyndication.com https://*.doubleclick.net https://*.googlesyndication.com <a href="https://www.googletagservices.com" rel="nofollow">https://www.googletagservices.com</a> https://*.googlesyndication.com <a href="https://www.google-analytics.com" rel="nofollow">https://www.google-analytics.com</a> https://*.googlesyndication.com <a href="https://d3clqjduf2gvxg.cloudfront.net" rel="nofollow">https://d3clqjduf2gvxg.cloudfront.net</a> https://*.googlesyndication.com https://*.firebaseio.com https://*.googlesyndication.com https://*.opentok.com https://*.googlesyndication.com Either the 'unsafe-inline' keyword, a hash ('sha256-...'), or a nonce ('nonce-...') is required to enable inline execution. Error 2) Refused to execute inline script because it violates the following Content Security Policy directive: "script-src 'self' 'unsafe-eval' https://*.googlesyndication.com https://*.doubleclick.net https://*.googlesyndication.com <a href="https://www.googletagservices.com" rel="nofollow">https://www.googletagservices.com</a> https://*.googlesyndication.com <a href="https://www.google-analytics.com" rel="nofollow">https://www.google-analytics.com</a> https://*.googlesyndication.com <a href="https://d3clqjduf2gvxg.cloudfront.net" rel="nofollow">https://d3clqjduf2gvxg.cloudfront.net</a> https://*.googlesyndication.com https://*.firebaseio.com https://*.googlesyndication.com https://*.opentok.com https://*.googlesyndication.com Either the 'unsafe-inline' keyword, a hash ('sha256-...'), or a nonce ('nonce-...') is required to enable inline execution. Warning 1) 'Attr.nodeValue' is deprecated. Please use 'value' instead. Warning 2) Mixed Content: The page at ' <a href="https://app.roll20dev.net/editor/" rel="nofollow">https://app.roll20dev.net/editor/</a> ' was loaded over HTTPS, but requested an insecure image ' <a href="http://imgsrv.roll20.net:5100/?src=paizo.com/image/content/Logos/PathfinderRPGLogo_500.jpeg" rel="nofollow">http://imgsrv.roll20.net:5100/?src=paizo.com/image/content/Logos/PathfinderRPGLogo_500.jpeg</a> '. This content should also be served over HTTPS. I am completely clueless about the errors, but the warnings seem to be dealing with the Pathfinder Legacy character sheet I copied into custom character sheet to work on updates for that sheet. I really appreciate you taking a look at this over the weekend, and I hope the data I just provided is useful.