actor property
The delegate's VID — the party whose proof actually authenticated this session —
when this session was established by a proxied login (auth/authenticate/0.3,
payload.principal present and distinct from issuer). Absent whenever subject
authenticated with its own key, including every auth/authenticate/0.1 and /0.2
session and an auth/authenticate/0.3 request where principal is absent or equals
issuer. Carrying actor separately from subject is what lets an audit trail, a
revocation, or a response to a compromised delegate name the true acting party
without conflating it with the principal it acted for — see auth/authenticate/0.3
Security & Privacy (Correlation).
Implementation
final String? actor;