Build a viewer link
The auth token comes from your internal system (whatever issued it
after login) - this page doesn't mint or sign anything, it just
assembles the /watch URL. The watch page resolves the
username by asking the internal system's check-username API for the
token you paste in.
Viewer link (for embedding in an allowed page's <iframe> -
/watch refuses to open directly, see below):
Preview - only renders if this origin is in config/allowed-embed-origins.json: