Additional custom claims.
Subject — the user's unique ID.
OptionalissIssuer — typically your Supabase project URL.
OptionalaudAudience — who the token is intended for.
OptionalexpExpiration time (seconds since epoch).
OptionaliatIssued at (seconds since epoch).
OptionalroleSupabase role (e.g. "authenticated", "anon").
OptionalemailUser's email address from Supabase Auth.
Optionalapp_Application-level metadata set via Supabase Auth admin APIs.
Optionaluser_User-editable metadata set via Supabase Auth.
Standard JWT claims as defined by RFC 7519, extended with Supabase-specific fields.
This is the raw JWT payload — use UserClaims for a normalized, camelCase view.
See
https://datatracker.ietf.org/doc/html/rfc7519#section-4.1