Validates the handoff code and returns a JWT token for subsequent requests. No authentication required (the handoff code serves as the credential).