Uncrypt SSO — sign-in complete
After login, the SSO service redirects to your return URL and appends the freshly
minted session token in the fragment (#access_token=…). Steal that token by choosing where
the flow returns to.
This is an isolated, intentionally-vulnerable sandbox. Data here is fake and scoped to you. The rest of Uncrypt Playground is not part of the target.