token should contain: * uid * firstname + lastname / name * phone (mobile) * email
token should contain: