OptionalaudOptionalemailOptionalexpOptionalfamily_Optionalgiven_OptionaliatOptionalissOptionalmj_The single Application this session is scoped to.
Optionalmj_Marks the session as magic-link so the host UI can confine it.
Optionalmj_The restricted role name assigned to this user (informational).
OptionalnameOptionalsub
Decoded claims of an MJ-issued magic-link session JWT.
Mirrors the claim set minted server-side (
MagicLinkJWTClaimsin MJServer's magic-link module). Declared independently here — NOT re-exported from the server package — so the client has a typed view without a cross-package dependency. All fields optional because the token is decoded without verification (the server validates via JWKS); never trust these for security decisions, only for UI display + app confinement.