Token Data
During the lifecycle of a request you will be able to access the data you have configured to be stored in the JWT by accessing req.user. The user object is automatically appended to the request for you.
Defining Token Data
You can specify what data gets encoded to the Cookie/JWT-Token by setting saveToJWT property on fields within your auth collection.
Decoding a token produces the same flat token data shape used by earlier Payload versions:
Payload reserves id, collection, email, sid, iat, and exp; fields configured with saveToJWT cannot replace these values. All other fields selected by saveToJWT, including fields that use a custom string key, are stored at the top level with the trusted authentication values.
Payload also signs authVersion: 1 into the token's protected JWT header. This marker identifies tokens issued by the fixed authentication format and is checked during authentication. It is not a decoded payload field, because an existing saveToJWT alias could use that name.
Using Token Data
This is especially helpful when writing Hooks and Access Control that depend on user defined fields.
Was this page helpful?