When the server receives the request it can simply decrypt the token and deserialize it into some sort of strongly typed usercontext.
When the server receives the request it can simply decrypt the token and deserialize it into some sort of strongly typed usercontext.