CSPSHIVAM SSO — sign-in complete
After login, the SSO service redirects to your return URL and appends the freshly
minted session token in the fragment (#access_token=…). Steal that token by choosing where
the flow returns to.
Stuck? You've missed the flag a few times. The full solution — root cause, exact payload and fix — is on the walkthrough page.
Check the solution on the walkthrough page →This is an isolated, intentionally-vulnerable sandbox. Data here is fake and scoped to you. The rest of CSPSHIVAM Playground is not part of the target.