Portal Session
The credential a completed Client Auth login resolves to.
Pass it straight to Portal(credentials = …). It is a PortalCredentials like any other, so nothing downstream of Portal knows or cares that the token came from Client Auth rather than from a custodian-issued Client API Key.