So, from an external site...
Firstly, MODX encapsulates the valid access within its environment, by checking its own session.
There is no anonymous permission to the restricted docs. It's simply not logic.
There must be several ways to manipulate this, and I will try to give a shot my own thought.
Objectives:
1. Cloning the users between those different domains.
2. Activating the valid user's session by using a 'bridge' snippet.
Procedures:
1. I always think that the MODX installation is an advanced distro, because in this distro the core/ folder can be moved to outside of the web root. What we'd need in that core/ folder is the $modx object.
2. Create a hidden but published resource with a plain blank template, with the 'bridge' snippet in it, and nothing else. This resource is the one that will pull the $modx object for your external site.
3. This 'bridge' snippet will check the MODX's user database whether the user is in the specified group with several permissions. This 'bridge' snippet will ALSO add the new user in parallel with the external site's user registering.
4. Your external site have a script that loads the MODX's restricted resource by using a cURL or file_get_contents. But check this
benchmark before you choose.
5. That script is also responsible on registering the new user to the MODX's system.
6. You can use cross-domain AJAX to do this.
That's roughly.
Btw, it's a complicated work, I suggest you don't do this way.

Why do you want MODX serves as a 'slave' site?