any of request, webauthnCredentialId, dpopJkt,
deviceSecret, clientId (the application the device is linked to)
and subject (the username the request is for, which sets
ownerMatches)
the fact { id, via, keyId, owner, ownerKind, ownerName, status, attestation, compliance, … }, or null when no device is recognised
Recognises the registered device a request's evidence names.
When several devices are named, the strongest evidence wins and the others are listed in
conflict. A compromised device is still recognised. Moves the device's last use and counts the recognition.