Check whether an access token is valid, and if so, what scopes and identity it grants. A bearer token should be passed in the Authorization header of the request.
Response
Inactive Token
Whether the token is currently active and usable. Returns false for invalid or expired tokens.
Active Token
Whether the token is currently active and usable. Returns true for valid tokens.
A space-separated list of scopes associated with this token.
The app ID of the OAuth app that requested this token.
token_type
string
default:"Bearer"
required
The type of token. Always "Bearer" for tokens acquired via the OAuth 2.0 flow.
The time at which this token will expire, if set, as a number of seconds since January 1 1970 UTC.
The time at which this token was issued, as a number of seconds since January 1 1970 UTC.
Since Bearer tokens grant workspace-level permissions, this property contains the workspace ID.
The intended audience for this token. For Bearer tokens this is the same as the client_id.
iss
string
default:"attio.com"
required
The issuer of the token. Always "attio.com".
authorized_by_workspace_member_id
The ID of the workspace member who authorized this token initially.
The ID of the workspace the token is scoped to.
The name of the workspace the token is scoped to.
The slug of the workspace the token is scoped to.
The logo URL of the workspace the token is scoped to.