Workflow or API calls:

We are going towards Sandbox in our calls to FHIR. But should we also go towards Sandbox in the authorization URL?
Background Information:
We want to extract the logged in Millennium user's id from the access token. But we are unsure which part of the access token we should extract from?
The example below comes from the Sandbox environment.
Can we expect both of the two marked fields (“user”, “personnel”) to always be present in the access token?

We would like to use one of these two fields to identify who is logged in.
Can we expect it to look the same in the production environment?
Failure to provide answers will impact our ability to respond in a timely and effective manner
Developer questions:
Are you an OPN Member? Yes / No
Have you signed up to be in the Healthcare Developer Track? Yes / No
Are you a registered Code Program member? Yes / No
Does your App have a presence on the Oracle Healthcare App Marketplace? Yes / No
Are you developing on behalf of an Oracle Health client?
If so, which client:
Application's Client ID and App ID, if relevant:
"client": { "name": "RS Sweden Patient Fees (CERT)", "id": "bfe52b78-7613-4a60-9d85-d6a6398214d4" },
Expected Result:
Actual Result:
X-Request-Id / Cerner-Correlation-Id / opc-request-id:
Date/time of the example: 2025 - Oct - 21