Mint a one-time cross-origin session handoff code
For apps/portal (hosted auth UI, a different origin than the tenant’s app_url) to hand its session off after redirecting - the code, not the session itself, travels through the URL.
POST
Mint a one-time cross-origin session handoff code
Authorizations
App identifier (App.id, sent as the x-app-id header)

