Card simulator
A cross-site iframe at the box X actually gives the card, with X's reported sandbox. Develop the invest flow here instead of deploying.
Same-site — results here are not trustworthy.
Open this page on
Open this page on
http://127.0.0.1 or http://localhost so the frame can cross to the other host. Framing the same host gives the card first-party storage, which hides every partitioning bug it will hit inside X.Local and dev databases carry different baskets —
a slug from production will 404 here.
a slug from production will 404 here.
540 × 545 — X web timeline
What this does and does not prove
Reproduces: cross-site storage partitioning, X's sandbox flags, the real card box, and popup inheritance (no allow-popups-to-escape-sandbox).
Does not reproduce: having x.com as the top-level origin. Anything that depends on who the top frame is — above all whether Privy's own iframe tolerates sitting three deep — still needs a posted tweet.
Open devtools on the frame to debug. Console logs from the card are prefixed [cesto-auth] and [cesto-invest].