Decoded JWT or synthetic auth payload attached to a request.
Subject identifier (user or service name).
Granted authorization scopes.
Optional
JWT "issued at" timestamp (epoch seconds).
JWT expiration timestamp (epoch seconds).
Decoded JWT or synthetic auth payload attached to a request.