User Context
StructThe complete user execution context. Use 'Break Struct' to access: sub, role (with id, name, permissions, attributes), isTechnicalUser, keyId, principal, originAppId, onBehalfOf
User subject identifier (e.g., OIDC sub claim) Empty for technical users (API keys, app connections)
Role information
Role context containing role metadata and permissions
Role ID
Role name
Role permissions as a bitfield
Custom attributes assigned to the role
Custom key-value attributes that can be set by users
Whether this is a technical user (API key, app connection) rather than a human user
For API keys, the key identifier. Never set for other principals.
Which kind of principal started the run.
A human account: an OIDC session or a personal access token.
An app-scoped API key. Carries no human subject of its own.
Another app calling through an app connection.
For `ConnectedApp`, the app that made the call.
Subject the calling principal reported as the initiator: the API key's creator, or the user an app connection passed through. Attribution only — the run must never treat it as an identity it may act as.