Newtype wrapping the raw access-token JWT presented by the caller.
MCP tool handlers that delegate to AuthPlane’s token-exchange flow need
the original JWT for the subject_token field. The verified-claims
extension (VerifiedClaims) intentionally drops the raw token, so
middleware that authenticates a request should stash it alongside the
claims as RawAccessToken for downstream extraction.
Transparent wrapper per the API convention documented in
CONTRIBUTING.md: the inner String is pub because there are no
invariants to enforce — the JWT shape is enforced by the verifier, not
by this wrapper. Compare with InboundDPoPOptions, which carries
validation invariants and keeps its fields private.
Exported here so consumers don’t reinvent the newtype in each codebase.
See demo/http_calculator_demo.rs for the wiring pattern.