Cookie-based handoff pattern for existing users in the get-started flow. After OTP verification detects portal_exists, BFF sets a short-lived HttpOnly cookie and redirects to the login page, which shows a password-only form (no second OTP).
Cookie-based handoff pattern for existing users in the get-started flow. After OTP verification detects portal_exists, BFF sets a short-lived HttpOnly cookie and redirects to the login page, which shows a password-only form (no second OTP).