Browser.openAuthSessionAsync() → Vipps page → user opens Vipps app → approves login https://api.mydomain.com/auth/oauth2/callback/vipps?state=xxx&code=xxx myapp:///?cookie=xxx, Safari shows the “Open in App?” alert → app is opened.cookie query param and sets it like this:state_mismatch from Better Auth during this callback: