The authority strategy being used
Would expect three possible types of strategy pertaining to "Role" info:
Groups, Roles, and Scope
For API Resource Server using JWT Tokens - `scope` is the default
Configurable via auth0.properties file
Convenience Utils methods for manipulating the nonce key/value pair held in state param
Used for CSRF protection - should always be sent with login request