The signin token creation process does not seem to actually require a valid session. So right now if you attempt to launch a session, it won’t fail until you get to the browser.
It may be worth adding a get_caller_identity call before creating the signin token to fail earlier.