Every claim, for the app's own use (display name, email).
OptionalclientThe client the token was issued to (azp): kiban-frontend for a browser login, a
service client id for a client-credentials token.
The subject (sub): the user's Keycloak id, which is the subjectId Kiban's tuples name.
The verified identity a Kiban token carries. Identity only, never authority: ask Kiban for every access decision.