This is the browser redirect carrying request_token after sign-in, not an order-update postback or webhook. The hostname above is only an example.
1. Will both app registration and the live browser-login flow accept this explicit HTTPS port? 2. For an owner-only test, can inbound access to that callback listener be restricted to the signing-in user's public IP, or does Kite need to make any server-to-server verification request to the redirect URL? 3. If port 8443 is not supported, what HTTPS port restrictions apply specifically to login redirects?
The request_token exchange would remain server-side. I checked the v3 login documentation, but could not find an explicit supported-port list for browser-login redirects. Thank you.