OptionalaccessCognito access token.
OptionalexpiresEpoch ms when the idToken expires (derived from its exp claim).
OptionalidCognito ID token — the bearer token the platform actually accepts.
OptionalrefreshCognito refresh token, used to obtain fresh access/id tokens.
OptionalserviceService-account key pair (backend support pending, D7).
The session shape a
CredentialStorepersists between requests/processes.