Determine the active state of an OAuth 2.0 token and obtain meta-information about it (see OAuth 2.0 Token Introspection — RFC 7662). The endpoint requires client authentication and returns { active: false } for any token that is unknown, expired, or revoked.
Client ID. May also be supplied via Authorization: Basic or a client_assertion (JWT). Required when the client is configured with client_secret_post.
- Sandbox environmenthttps://api.sbx.transmitsecurity.io/cis/oidc/token/introspection
- US production environmenthttps://api.transmitsecurity.io/cis/oidc/token/introspection
- EU production environmenthttps://api.eu.transmitsecurity.io/cis/oidc/token/introspection
- CA production environmenthttps://api.ca.transmitsecurity.io/cis/oidc/token/introspection
- AU production environmenthttps://api.au.transmitsecurity.io/cis/oidc/token/introspection
- JP production environmenthttps://api.gasne1-ts01.transmitsecurity.io/cis/oidc/token/introspection
curl -i -X POST \
https://api.sbx.transmitsecurity.io/cis/oidc/token/introspection \
-H 'Content-Type: application/x-www-form-urlencoded' \
-d client_id=string \
-d client_secret=string \
-d token=string \
-d token_type_hint=access_tokenResponse
{ "active": false }