Token.
The claims of an access token; the gateway checks six of them and grants nothing on the token alone
Figure 1Tokenspecified
- kind
- value
- scope
- none
- key
- none
- store
- none
- family
- people
Fields#
| field | type | required | note |
|---|---|---|---|
token_use | one of access | yes | it is marked as an access token |
subject | text | yes | |
issuer | address | yes | |
client | id | yes | which client it was given to |
audience | text | yes | which service it is made out to |
expires_at | time | yes | |
signed_in_strength | text | no | |
signed_in_at | time | no | |
access_scopes | AccessScope | yes | |
acting_for | [text] | no | outermost first |
bound_key | hash | no | the holder’s key it is tied to |
Routes that use it#
No route takes or returns Token directly. The record holds it, and the objects that point at it reach it.