Hi Scott,
The new built-in JWT support in Verify Access 10 (using the [jwt...] stanza) only supports building claims from credential attributes or fixed strings.
If you were to move to using the "TFIM SSO" junction option you would be able to generate the JWT in the federation add-on STS and have full control over content - including call out to external REST services. Bit pretty sure this is not possible in the new built in version.
One other option would be to have whatever is building the credential at login populate the attributes you need at that point so the built in JWT code can just use them as-is from the credential. Not useful if you are just using built-in authentication though.
Jon.
------------------------------
Jon Harry
Consulting IT Security Specialist
IBM
------------------------------