Request a login link for an email, read the captured link from the inbox side channel (a mock mailbox at /api/lab/inbox), then visit it. The link is single-use: replaying the same token returns 410 Gone.
Real-world parallel: passwordless / "magic link" auth where the credential never lives in the UI โ the automation lesson is reading an external channel and doing a fresh navigation on the captured URL.