Start a managed link
Enableidentity-links:create on the application’s proxy token and register the
exact return URL in Settings → Organization → Proxy tokens.
In a server route, verify the application’s session, check the same-origin
mutation, and load the user’s identity from your database. Call the unbound
application client: