the requested token type
the subject
the audience
the lifetime in minutes
how the requester authenticated; unspecified when absent
Optionaldelegates: any
#186: the parties that acted for the subject, least to most recent; none when absent
the token's XML, its reference, its token type and its id
Builds the token that goes inside
wst:RequestedSecurityToken: a signed SAML 2.0 assertion, or a JWT in a BinarySecurityToken when the token type asks for one.