Must be admin to invoke (api is fine too), uses same sso payload nonce is ignored
/category/xyz
/c/xyz