Web application RP1 offers sign in/sign up functionality for users of identity provider IDP1, using OpenID Connect code flow.
Ignoring how IDP1 authenticates the user, apart from the fact that successful auth results in a cookie in IDP1 domain.
Notable: ID Token is obtained server side, no user agent access.