The generated JWT token for API authentication. This token is signed with the server's secret key and has the "api" audience. The token does not expire but can be invalidated by updating the user's min_issued_at. Should be stored securely as it grants full access as the specified user.
Response message containing the newly generated API token.