Interesting choice to require users to already be logged into the browser. Was that primarily to avoid dealing with authentication flows and anti-bot measures?
Alternative is it do it separately from user flow (in different browser, and solve whole new set of complexities, for no real gain), e.g. in headless browser (which sucks for anti-bot).
I am not really into catch your tail game of anti-bot measures, which are not static but evolve in time. If I tap into what user actually does, I have won a game, no need to re-do it forever.