the authorization server's base URL
the grant's facts: client_id, username or user,
scope, audience, jkt, authorization_details, claims, acr,
amr, auth_time, act, grant, request and the rest — and
access_jti / status_ref from reserveAccessToken()
the signed token
Mints an RFC 9068 access token for a grant, with its audience, scope and sender constraint, and records it with the token registry.