A: Firebase ID token from configured flow B: POST Firebase OAuth exchange C: Wallkit session token D: GET content access check E: Application handles the content decision A → B: Send firebase-token + resource; creation flag false B → C: Already-linked success: HTTP 200, existed true A → D: Keep matching ID token C → D: Send token + firebase-token + same resource D → E: Read allow separately from identity