Yes, I saw, and implemented. Thanks.
The thing is when I login this way, the browser never visits the auth server, and thus does not get a cookie. So there is no SSO. I was wondering if there was some susequent redirect that I could use, with the access token, that would allow the user to get the SSO cookie without being challenged on the auth screen.