We would like to use the Token Authenticator URL instead of Personal Links. However, we don't understand how an external system is expected to generate the ssotoken.
We can see the Token Authenticator configuration (encryption method, MAC method, shared secret key, etc.), but we're unable to find documentation explaining how these parameters are used to generate the token.

Does anyone have an example or documentation that explains the token generation logic and expected payload format?
Thanks in advance for your help.
