After twofa verifies identity, re-visit connect/login as authenticated user.
Zerodha then redirects to the registered callback URL with request_token.
This mirrors what the browser JS does to complete the OAuth flow.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>