The token to pass as the tag's session-token attribute.
When the token expires; re-mint and call refresh(token) before then.
OptionalgraphqlWhere the patient-side surface lives, so a browser client is
SELF-CONFIGURING: hand this whole response to @natzar/client's browser
half and it knows how to connect. Deliberately returned per-mint rather
than published as a constant — the key rotates (AppSync keys expire), and
a value baked into your bundle would break at a moment unrelated to
anything you shipped.
Absent on older deployments; a client that does not see them should fall back to relaying calls through your own server.
OptionalpublicPublic, browser-safe API key for the patient-side surface — the transport
credential only. The real credential is sessionToken, which is scoped to
one patient (and, for consult sessions, one consult). Publishable in the
same sense as a Stripe publishable key.
Response of the
/embed-sessionmints (both consult kinds): a fresh session token for the consult's patient-facing embed widget.