# Token Data

Source: https://payloadcms.com/docs/beta/authentication/token-data

During the lifecycle of a request you will be able to access the data you have configured to be stored in the JWT by accessing `req.user`. The user object is automatically appended to the request for you.

### Defining Token Data

You can specify what data gets encoded to the Cookie/JWT-Token by setting `saveToJWT` property on fields within your auth collection.

```ts
import type { CollectionConfig } from 'payload'

export const Users: CollectionConfig = {
  slug: 'users',
  auth: true,
  fields: [
    {
      // will be stored in the JWT
      saveToJWT: true,
      type: 'select',
      name: 'role',
      options: ['super-admin', 'user'],
    },
    {
      // the entire object will be stored in the JWT
      // tab fields can do the same thing!
      saveToJWT: true,
      type: 'group',
      name: 'group1',
      fields: [
        {
          type: 'text',
          name: 'includeField',
        },
        {
          // will be omitted from the JWT
          saveToJWT: false,
          type: 'text',
          name: 'omitField',
        },
      ],
    },
    {
      type: 'group',
      name: 'group2',
      fields: [
        {
          // will be stored in the JWT
          // but stored at the top level
          saveToJWT: true,
          type: 'text',
          name: 'includeField',
        },
        {
          type: 'text',
          name: 'omitField',
        },
      ],
    },
  ],
}
```

> **Tip:**
>
> If you wish to use a different key other than the field `name`, you can define `saveToJWT` as a string.

Decoding a token produces the same flat token data shape used by earlier Payload versions:

```ts
{
  id: 'user-id',
  collection: 'users',
  email: 'user@example.com',
  sid: 'session-id', // when sessions are enabled
  role: 'super-admin', // fields configured with saveToJWT
  iat: 1750000000,
  exp: 1750007200,
}
```

Payload reserves `id`, `collection`, `email`, `sid`, `iat`, and `exp`; fields configured with `saveToJWT` cannot replace these values. All other fields selected by `saveToJWT`, including fields that use a custom string key, are stored at the top level with the trusted authentication values.

Payload also signs `authVersion: 1` into the token's protected JWT header. This marker identifies tokens issued by the fixed authentication format and is checked during authentication. It is not a decoded payload field, because an existing `saveToJWT` alias could use that name.

### Using Token Data

This is especially helpful when writing [Hooks](/docs/v4/hooks/overview.md) and [Access Control](/docs/v4/access-control/overview.md) that depend on user defined fields.

```ts
import type { CollectionConfig } from 'payload'

export const Invoices: CollectionConfig = {
  slug: 'invoices',
  access: {
    read: ({ req, data }) => {
      if (!req?.user) return false
      // highlight-start
      if ({ req.user?.role === 'super-admin'}) {
        return true
      }
      // highlight-end
      return data.owner === req.user.id
    }
  }
  fields: [
    {
      name: 'owner',
      relationTo: 'users'
    },
    // ... other fields
  ],
}
```
