Introspect OAuth2 Access and Refresh Tokens
POST/admin/oauth2/introspect
The introspection endpoint allows to check if a token (both refresh and access) is active or not. An active token is neither
expired nor revoked. If a token is active, additional information on the token will be included. You can set additional data for a
token by setting session.access_token during the consent flow.
SDK ReferenceTypeScript
introspectOAuth2Token()| Parameters | Type | Required | Description |
|---|---|---|---|
| token | string | required | The string value of the token. For access tokens, this is the "access_token" value returned from the token endpoint defined in OAuth 2.0. For refresh tokens, this is the "refresh_token" value returned. |
| scope | string | optional | An optional, space separated list of required scopes. If the access token was not granted one of the scopes, the result of active will be false. |
| Variable | Type |
|---|---|
| data | IntrospectedOAuth2Token |