Two steps: (1) read the viewer’s JWT out of a verbose error body cross-origin, (2) replay it to fetch the account’s PII. The PII is POSTed to this server as proof.
access_token cookie (the app writes it as Bearer <jwt>).
Open any LendingTree form first if not.