Token Introspection

The App's Server introspects the issued token.

Comply with RFC7662

NOTE

  1. Content-Type MUST be application/x-www-form-urlencoded;
  2. The App MUST authenticate itself, via either Secret Basic or Secret Post method;
  3. Content-Type of the response is application/json;charset=UTF-8;
  4. If the token provided is issued to another App, the Authorization Server will respond with "inactive";
  5. For explanation of errors, please refer to Section 5.2 of RFC6749.

Example

token: eyJhbGciOiJSUzI1NiIsImtpZCI6Im1mNXZkMWR6IiwidHlwIjoiSldUIn0.eyJjbGllbnRfaWQiOiIzZThhN2EwYzM5Y2U0YWE0YWQyNjU1YjcwYTVkOTk1ZSIsImV4cCI6MTY0Mzg4Njk4OCwiaWF0IjoxNjQzMDIyNzUzLCJpc3MiOiJodHRwczovL3Rlc3Qtb2F1dGgudGlnZXJmaW50ZWNoLmNvbS9vYXV0aDIiLCJqdGkiOiI1M2NhOTc1Ni1jN2U3LTQ1MzAtOGFhNC0wMzQxMGE1MjM4MmMiLCJuYmYiOjE2NDMwMjI3NTMsInNjcCI6WyJ1dWlkIiwib2ZmbGluZSJdLCJzdWIiOiI1MzQ4OTUwNTUxMjc0In0.n7QvvPd4RjSQEXLEoXvY3Ytjxks3FHHNtbuhFuDZaXPB3UKxsLC79YRaj6C1ZIRdMps02IHxrxruq9Mf2bOygHUccYOtl56noLjfpkZNIhgVy-DpbGu8LuVyWWEnTeuBbBDpmraTM49bJyPMIZ5Ze8k8LKQRuYrsXEGW6ZGtE3bwM94-ZLdRtPrutxNS-BlzLuPovpERdWMVprUS5OJ9E2J8h3pUM5QT4xQ-zZeDpjSKaGs4WCW8bA1qAVpXO4vzALm3AnPoH1k4_Gsxx0zsw-92D8TjvVIAlcRbZ3_XNj_IcP2YlQ5SNd03yw_1qoOzrvbpc3VGTmP5exGPmwIJtw
token_type_hint: access_token
scope: uuid offline
Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Form Data
string
required

The token to introspect

string
enum

Token type hint.

Allowed:
string

The scopes that the App intends to check, concatenate multiple scopes with ' '.

string

Used by Secret Post authentication method

string

Used by Secret Post authentication method

Responses

Language
Credentials
Basic
base64
:
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json