OptionalemailPrimary email address, when included in the access token.
OptionalemailWhether Keycloak has verified KeycloakOAuthUser.email.
OptionalfamilyFamily name, when included in the access token.
OptionalgivenGiven name, when included in the access token.
Keycloak subject identifier.
OptionalnameDisplay name, when included in the access token.
OptionalpreferredPreferred username, when included in the access token.
OptionalrealmUnmodified realm_access claim, when present.
OptionalresourceUnmodified resource_access claim, when present.
Realm roles from realm_access.roles.
Verified Keycloak user and role claims exposed to authenticated MCP callbacks.