Your frontend can use this to render a preview of the transaction before the counterparty signs in. The token itself is opaque - call this endpoint to resolve it.
This endpoint is unauthenticated because the invitee may not yet have an account. The token is single-use and expires after 30 days.