> ## Documentation Index
> Fetch the complete documentation index at: https://docs.bijection.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Interface: UserIdentity

> Information about an authenticated user, derived from a JWT.

[server](/api/modules/server).UserIdentity

Information about an authenticated user, derived from a
[JWT](https://datatracker.ietf.org/doc/html/rfc7519).

The only fields guaranteed to be present are
[tokenIdentifier](/api/interfaces/server.UserIdentity#tokenidentifier) and [issuer](/api/interfaces/server.UserIdentity#issuer). All
remaining fields may or may not be present depending on the information given
by the identity provider.

The explicitly listed fields are derived from the OpenID Connect (OIDC) standard fields,
see the [OIDC specification](https://openid.net/specs/openid-connect-core-1_0.html#StandardClaims)
for more information on these fields.

Any additional fields are custom claims that may be present in the JWT,
and their type depends on your identity provider configuration. If you
know the type of the field, you can assert it in TypeScript like this
(for example as a `string`):

```typescript theme={"theme":{"light":"github-light-default","dark":"github-dark-default"}}
const identity = await ctx.auth.getUserIdentity();
if (identity === null) {
  return null;
}
const customClaim = identity.custom_claim as string;
```

## Indexable

▪ \[key: `string`]: [`JSONValue`](/api/modules/values#jsonvalue) | `undefined`

## Properties

### tokenIdentifier

• `Readonly` **tokenIdentifier**: `string`

A stable and globally unique string for this identity (i.e. no other
user, even from a different identity provider, will have the same string.)

JWT claims: `sub` + `iss`

***

### subject

• `Readonly` **subject**: `string`

Identifier for the end-user from the identity provider, not necessarily
unique across different providers.

JWT claim: `sub`

***

### issuer

• `Readonly` **issuer**: `string`

The hostname of the identity provider used to authenticate this user.

JWT claim: `iss`

***

### name

• `Optional` `Readonly` **name**: `string`

JWT claim: `name`

***

### givenName

• `Optional` `Readonly` **givenName**: `string`

JWT claim: `given_name`

***

### familyName

• `Optional` `Readonly` **familyName**: `string`

JWT claim: `family_name`

***

### nickname

• `Optional` `Readonly` **nickname**: `string`

JWT claim: `nickname`

***

### preferredUsername

• `Optional` `Readonly` **preferredUsername**: `string`

JWT claim: `preferred_username`

***

### profileUrl

• `Optional` `Readonly` **profileUrl**: `string`

JWT claim: `profile`

***

### pictureUrl

• `Optional` `Readonly` **pictureUrl**: `string`

JWT claim: `picture`

***

### email

• `Optional` `Readonly` **email**: `string`

JWT claim: `email`

***

### emailVerified

• `Optional` `Readonly` **emailVerified**: `boolean`

JWT claim: `email_verified`

***

### gender

• `Optional` `Readonly` **gender**: `string`

JWT claim: `gender`

***

### birthday

• `Optional` `Readonly` **birthday**: `string`

JWT claim: `birthdate`

***

### timezone

• `Optional` `Readonly` **timezone**: `string`

JWT claim: `zoneinfo`

***

### language

• `Optional` `Readonly` **language**: `string`

JWT claim: `locale`

***

### phoneNumber

• `Optional` `Readonly` **phoneNumber**: `string`

JWT claim: `phone_number`

***

### phoneNumberVerified

• `Optional` `Readonly` **phoneNumberVerified**: `boolean`

JWT claim: `phone_number_verified`

***

### address

• `Optional` `Readonly` **address**: `string`

JWT claim: `address`

***

### updatedAt

• `Optional` `Readonly` **updatedAt**: `string`

JWT claim: `updated_at`
