API origin, such as https://api.github.com; excludes the API path.
Provider-assigned account ID, represented as a string.
Hosting platform; combine with host and ID when comparing identities.
Provider-linked login; display names are never identity evidence.
Provider-qualified identity; IDs are strings to avoid numeric assumptions.