I have an api and an Angular SPA that\'s completely separate from it, and they have different origins/hosts, I figured out the implementation to be like this: The user gets into