embed token
Narrowly-scoped embed token for the iframe. Absent for fully anonymous or raw apps, which load without a scoped token.
Expiration of the embed token.
Raw apps render single-iframe and skip the opaque-viewer indirection and the embed token entirely.
Publisher opted this app into sandbox isolation. When false the viewer runs the app same-origin with its full session.
The resolved app path; the embedder uses it to scope the app's backing localStorage per app.
The resolved workspace; pairs with app_path so apps at the same path in different workspaces don't share a localStorage store.