---
title: "Changes to Introspect an OAuth token"
method: POST
path: "/oauth2/introspect"
---

# Changes to Introspect an OAuth token

`POST /oauth2/introspect`

> Every recorded change to this endpoint, newest first.

## Timeline

Changed in 3 of 7 revisions.

- **2026-03-18** `e271d0e41f6d` — 2 breaking, 3 info
- **2026-03-06** `61b60b0c0d52` — 1 info
- **2026-02-03** `fc0a40f3b859` — 1 breaking

## Changes

- **2026-03-18** `e271d0e41f6d` — 2 breaking, 3 info
  - request body became required
  - removed the media type `application/json` from the request body
  - api operation id `post_oauth2_introspect` removed and replaced with `postOauth2Introspect`
  - added the new optional `header` request parameter `XF-Api-User` to all path's operations
  - added the new optional `query` request parameter `api_bypass_permissions` to all path's operations
- **2026-03-06** `61b60b0c0d52` — 1 info
  - endpoint added
- **2026-02-03** `fc0a40f3b859` — 1 breaking
  - api path removed without deprecation

---

[Operation](https://skmtc.dev/xenforo-ltd/apis/xenforo-api/docs/oauth2/introspect/post.md) · [API](https://skmtc.dev/xenforo-ltd/apis/xenforo-api.md) · [Page](https://skmtc.dev/xenforo-ltd/apis/xenforo-api/changes/oauth2/introspect/post)
