Sign in with the ADMIN role to continue.
The token is exchanged via POST /auth/sso; the resulting session stays server-side.