OptionalemailOptionalnameOptionalpictureOIDC subject — the stable per-user identifier.
Optionalwallet_All wallets of the user, default entry included (multi-wallet
foundation, docs/28; requires the wallet scope).
Optionalwallet_The user's bound wallet address, once set (requires the wallet scope).
Optionalwallet_Reserved: the wallet's secp256k1 public key (compressed SEC1 hex;
requires the wallet scope). No issuer flow populates this claim today —
issuer-side pre-derivation was rejected (docs/34, 2026-08-20): the final
TSS key includes ceremony-time client randomness, so it cannot be known
before the first ceremony. If a future flow supplies it, both chain
addresses derive from it offline: see addressesFromPublicKey /
UpbondState.derivedAddresses.
Decoded id_token claims.
subis the stable user identifier (and the Web3AuthverifierId); the optional profile claims depend on the granted scope.wallet_addressis present once the address has been bound to the account. Unlisted claims are exposed via the index signature.