I don't believe that you can, and it is best that way, make a separate call to get the user's roles/claims.
By doing so you are keeping the appropriate separation of concerns (authentication & authorization). Keep the logic from determining who a user is separate from determining what the user can do. This way if you down the road you decide to replace just one of those two components you are not re-writing your entire client side.