Names the application that holds a credential: a token's client_id, an assertion's or SVID's audience, or a ticket's service.
client_id
an issued-credential record with its family
family
the holder, or an empty string when the credential has none
Names the application that holds a credential: a token's
client_id, an assertion's or SVID's audience, or a ticket's service.