Card simulator

A cross-site iframe at the box X actually gives the card, with X's reported sandbox. Develop the invest flow here instead of deploying.

Same-site — results here are not trustworthy.
Open this page on http://127.0.0.1 or http://localhost so the frame can cross to the other host. Framing the same host gives the card first-party storage, which hides every partitioning bug it will hit inside X.
Local and dev databases carry different baskets —
a slug from production will 404 here.
540 × 545 — X web timeline

What this does and does not prove

Reproduces: cross-site storage partitioning, X's sandbox flags, the real card box, and popup inheritance (no allow-popups-to-escape-sandbox).

Does not reproduce: having x.com as the top-level origin. Anything that depends on who the top frame is — above all whether Privy's own iframe tolerates sitting three deep — still needs a posted tweet.

Open devtools on the frame to debug. Console logs from the card are prefixed [cesto-auth] and [cesto-invest].