POST /oauth/callback with id_token parameter
The server accepts ANY JWT without signature verification