I\'m using OpenIddict 2 to protect my API endpoints, and at the moment the user receives the roles that they have in the application in their authentication token.
Someti