Log in on this host first (POST /api/newlogin) so the token cookie is sent.
Submitting starts GET /api/sslzcheckout with bo_in_id and payment_amount; the server responds with a redirect to SSLCommerz.
bo_payment_info row exists yet, checkout creates one (same as POST /api/init-payment-status)./sslzcheckout.SSLCZ_SANDBOX in .env.