Paste what they sent, or drop the file they downloaded. You get a plain list of what is different, a preview of the real page with it applied, and one button that publishes it.
A token lives in one browser only — connecting on the laptop does not connect the
phone. The quickest one that works here is a classic token with the
public_repo scope; the button above opens it with that already ticked.
Approve writes data/lta-epk.json straight to the site using the token
already saved in Admin — the same one the rest of Admin uses. The site rebuilds in
about a minute. Reject opens a reply to whoever sent it, with your reason and the
set list already in it — nothing is published and nothing is lost, they can edit
and send again.