New Ory Agent Security is now live! Claim your complimentary test drive. Get Started!

Skip to main content

Introspect OAuth2 Access and Refresh Tokens

POST 

/admin/oauth2/introspect

The introspection endpoint allows to check if a token (both refresh and access) is active or not. An active token is neither expired nor revoked. If a token is active, additional information on the token will be included. You can set additional data for a token by setting session.access_token during the consent flow.

SDK ReferenceTypeScript
introspectOAuth2Token()
ParametersTypeRequiredDescription
tokenstringrequiredThe string value of the token. For access tokens, this is the "access_token" value returned from the token endpoint defined in OAuth 2.0. For refresh tokens, this is the "refresh_token" value returned.
scopestringoptionalAn optional, space separated list of required scopes. If the access token was not granted one of the scopes, the result of active will be false.
VariableType
dataIntrospectedOAuth2Token