#carrvo[d]I found that the browser was redirected to the IdP who returned the access code during its redirect back to the client. Then the client swapped the access code (given by the browser during redirect) for the access token. At least with SelfAuth and MinToken.