Sign in against the Laravel API to enter the real app shell.
Use the real Laravel login endpoint and store a secure app token in the browser session.