Skip to content

Introspection

Request

Determine the active state of an OAuth 2.0 token and obtain meta-information about it (see OAuth 2.0 Token Introspection — RFC 7662). The endpoint requires client authentication and returns { active: false } for any token that is unknown, expired, or revoked.

Bodyapplication/x-www-form-urlencodedrequired
client_idstring

Client ID. May also be supplied via Authorization: Basic or a client_assertion (JWT). Required when the client is configured with client_secret_post.

client_secretstring

Client secret. Required when the client is configured with client_secret_post.

tokenstringrequired

The token to introspect (access token or refresh token).

token_type_hintstring

Hint about the type of token submitted for introspection.

Enum:"access_token""refresh_token"
curl -i -X POST \
  https://api.sbx.transmitsecurity.io/cis/oidc/token/introspection \
  -H 'Content-Type: application/x-www-form-urlencoded' \
  -d client_id=string \
  -d client_secret=string \
  -d token=string \
  -d token_type_hint=access_token

Responses

Introspection response. The body shape depends on whether the token is active and, if so, what kind of token it is — see the response schema variants.

Bodyapplication/json
One of:

Returned when the token is unknown, expired, or revoked.

activebooleanrequired

Always false.

Value:false
Response
{ "active": false }