---
title: "Introspect an OAuth token"
method: POST
path: "/api/oauth/introspect"
tags: ["OAuth 2.0 / OpenID Connect"]
---

# Introspect an OAuth token

`POST /api/oauth/introspect`

## Response `200`

Token activity and metadata.

- OAuthIntrospectionResponse
  - `active` boolean, required
  - `scope` string
  - `client_id` string
  - `username` string
  - `token_type` string
  - `exp` integer
  - `iat` integer
  - `sub` string
  - `aud` union
    - string
    - string[]
  - `iss` string

## Other responses

- `400` — Validation error or precondition failure.
- `401` — Missing or invalid credential.
- `403` — Credential lacks the required scope (Agent Key) or insufficient OAuth scope.
- `404` — Resource does not exist or is invisible to the caller. The two are intentionally indistinguishable.
- `409` — Conflicting state (e.g. legal-entity name already taken).
- `429` — Rate limit exceeded. No `Retry-After` header is currently emitted; back off exponentially.
- `500` — Server error.

---

[API](https://skmtc.dev/eprospera/apis/e-pro-spera-api.md) · [All operations](https://skmtc.dev/eprospera/apis/e-pro-spera-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/eprospera/e-pro-spera-api/revisions/9ecdd3ca5a8c/schema)
