Validates the second-factor code that was issued during login or MFA setup. For login challenges, a new session cookie is issued when the supplied code is valid.
Session token stored in a cookie after user signs in, prefixed with __Secure if on https
The string (id or name, depending on the credentials)