Reference callback
A real app should run these checks server-side, reject replayed token IDs, then immediately start its own AT Protocol OAuth flow using the selected DID or handle as a login hint.
The example app or docs console will send you back here with `selection_token`, `client_id`, and `state` query parameters.