Skip to main content
POST
Introspect
Check whether an access token is valid, and if so, what scopes and identity it grants. A bearer token should be passed in the Authorization header of the request.

Response

Inactive Token

boolean
required
Whether the token is currently active and usable. Returns false for invalid or expired tokens.

Active Token

boolean
required
Whether the token is currently active and usable. Returns true for valid tokens.
string
required
A space-separated list of scopes associated with this token.
string
required
The app ID of the OAuth app that requested this token.
string
default:"Bearer"
required
The type of token. Always "Bearer" for tokens acquired via the OAuth 2.0 flow.
number | null
required
The time at which this token will expire, if set, as a number of seconds since January 1 1970 UTC.
number
required
The time at which this token was issued, as a number of seconds since January 1 1970 UTC.
string
required
Since Bearer tokens grant workspace-level permissions, this property contains the workspace ID.
string
required
The intended audience for this token. For Bearer tokens this is the same as the client_id.
string
default:"attio.com"
required
The issuer of the token. Always "attio.com".
string
required
The ID of the workspace member who authorized this token initially.
string
required
The ID of the workspace the token is scoped to.
string
required
The name of the workspace the token is scoped to.
string
required
The slug of the workspace the token is scoped to.
string | null
required
The logo URL of the workspace the token is scoped to.