Auth
Create origin handoff
Store encrypted client state for up to two minutes so another first-party web origin can redeem it once. The receiving origin must present the nonce whose SHA-256 digest is sent here.
post/auth/origin-handoff
Request body
Response
Success