v16

OpenAPI 3.0.3Apache 2.0raw.githubusercontent.com2026-04-0886158866.0 KB
Introspection Endpoint

Process OAuth 2.0 Introspection Request

This API exists to help your authorization server provide its own introspection API which complies with RFC 7662 (OAuth 2.0 Token Introspection).

post/api/{serviceId}/auth/introspection/standard

Path parameters

serviceIdstring required

A service ID.

Request body

parametersstring required

Request parameters which comply with the introspection request defined in "2.1. Introspection Request" in RFC 7662.

The implementation of the introspection endpoint of your authorization server will receive an HTTP POST [RFC 7231] request with parameters in the application/x-www-form-urlencoded format. It is the entity body of the request that Authlete's /api/auth/introspection/standard API expects as the value of parameters.

withHiddenPropertiesboolean

Flag indicating whether to include hidden properties in the output.

Authlete has a mechanism whereby to associate arbitrary key-value pairs with an access token. Each key-value pair has a hidden attribute. By default, key-value pairs whose hidden attribute is set to true are not embedded in the standard introspection output.

If the withHiddenProperties request parameter is given and its value is true, `/api/auth/introspection/standard API includes all the associated key-value pairs into the output regardless of the value of the hidden attribute.

rsUristring

The URI of the resource server making the introspection request.

If the rsUri request parameter is given and the token has audience values, Authlete checks if the value of the rsUri request parameter is contained in the audience values. If not contained, Authlete generates an introspection response with the active property set to false.

The rsUri request parameter is required when the resource server requests a JWT introspection response, i.e., when the value of the httpAcceptHeader request parameter is set to "application/token-introspection+jwt".

httpAcceptHeaderstring

The value of the HTTP Accept header in the introspection request.

If the value of the httpAcceptHeader request parameter is "application/token-introspection+jwt", Authlete generates a JWT introspection response. See "4. Requesting a JWT Response" of "RFC 9701: JWT Response for OAuth Token Introspection" for more details.

introspectionSignAlgstring

The JWS alg algorithm for signing the introspection response. This parameter corresponds to introspection_signed_response_alg defined in "6. Client Metadata" of "RFC 9701: JWT Response for OAuth Token Introspection".

The default value is RS256.

introspectionEncryptionAlgstring

The JWE alg algorithm for encrypting the introspection response. This parameter corresponds to introspection_encrypted_response_alg defined in "6. Client Metadata" of "RFC 9701: JWT Response for OAuth Token Introspection".

If the introspectionEncryptionAlg request parameter is specified, Authlete generates a JWT introspection response encrypted with the algorithm by this property and the algorithm specified by the introspectionEncryptionEnc request parameter.

introspectionEncryptionEncstring

The JWE enc algorithm for encrypting the introspection response. This parameter corresponds to introspection_encrypted_response_enc defined in "6. Client Metadata" of "RFC 9701: JWT Response for OAuth Token Introspection".

The default value is A128CBC_HS256.

sharedKeyForSignstring

The shared key for signing the introspection response with a symmetric algorithm.

The sharedKeyForSign request parameter is required when the introspection response is requested to be signed with a symmetric algorithm.

sharedKeyForEncryptionstring

The shared key for encrypting the introspection response with a symmetric algorithm.

The sharedKeyForEncryption request parameter is required when the introspection response is requested to be encrypted with a symmetric algorithm.

publicKeyForEncryptionstring

The public key for signing the introspection response with an asymmetric algorithm.

The publicKeyForEncryption request parameter is required when the introspection response is requested to be encrypted with an asymmetric algorithm.

Response

Token introspection completed successfully

resultCodestring

The code which represents the result of the API call.

resultMessagestring

A short message which explains the result of the API call.

action'INTERNAL_SERVER_ERROR' | 'BAD_REQUEST' | 'OK' | 'JWT'

The next action that the authorization server implementation should take.

responseContentstring

The content that the authorization server implementation is to return to the client application.