In case the user was authenticated with a passwordless link, the scope of the API token used for generating that link is inherited to the user session. This flag is true if the user would have more permissions than currently given by the passwordless link.