Handle / SubHandle ID (Base64URL of public key).
Handle / SubHandle name.
OptionalhDerivation path for SubHandle sessions.
Present only when the session was created by a SubHandle.
Format: [handleName, subName].
Intended audience.
Granted scopes.
Expiration timestamp (Unix seconds).
Issued-at timestamp (Unix seconds).
Unique session identifier, used for revocation. Always present (generated automatically if not provided).
The payload structure encoded inside a session token.