begin
Parameters
rawNonce
a fresh, cryptographically random, per-attempt value (see newRawNonce() in the platform source sets). Only its SHA-256 goes to Apple; the raw one goes to your server so it can prove the token was minted for this attempt.
state
a fresh random value, likewise per-attempt. It is the CSRF defence.