curl --request POST \
--url https://api.1password.com/v1/oauth/introspect \
--header 'Authorization: Basic <encoded-value>' \
--header 'Content-Type: application/x-www-form-urlencoded' \
--data token=op_o_c_H3WVOKGN4B7JXQYCQ6DJFAW5ZU_Q2s4ZmVnaGprbG1ub3BxcnN0dXZ3eHl6MDEyMzQ1Njc4OWFiconst encodedParams = new URLSearchParams();
encodedParams.append('token', 'op_o_c_H3WVOKGN4B7JXQYCQ6DJFAW5ZU_Q2s4ZmVnaGprbG1ub3BxcnN0dXZ3eHl6MDEyMzQ1Njc4OWFi');
const url = 'https://api.1password.com/v1/oauth/introspect';
const options = {
method: 'POST',
headers: {
Authorization: 'Basic <encoded-value>',
'Content-Type': 'application/x-www-form-urlencoded'
},
body: encodedParams
};
fetch(url, options)
.then(res => res.json())
.then(json => console.log(json))
.catch(err => console.error(err));import requests
url = "https://api.1password.com/v1/oauth/introspect"
payload = { "token": "op_o_c_H3WVOKGN4B7JXQYCQ6DJFAW5ZU_Q2s4ZmVnaGprbG1ub3BxcnN0dXZ3eHl6MDEyMzQ1Njc4OWFi" }
headers = {
"Authorization": "Basic <encoded-value>",
"Content-Type": "application/x-www-form-urlencoded"
}
response = requests.post(url, data=payload, headers=headers)
print(response.text)package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.1password.com/v1/oauth/introspect"
payload := strings.NewReader("token=op_o_c_H3WVOKGN4B7JXQYCQ6DJFAW5ZU_Q2s4ZmVnaGprbG1ub3BxcnN0dXZ3eHl6MDEyMzQ1Njc4OWFi")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Basic <encoded-value>")
req.Header.Add("Content-Type", "application/x-www-form-urlencoded")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}using RestSharp;
var options = new RestClientOptions("https://api.1password.com/v1/oauth/introspect");
var client = new RestClient(options);
var request = new RestRequest("");
request.AddHeader("Authorization", "Basic <encoded-value>");
request.AddParameter("token", "op_o_c_H3WVOKGN4B7JXQYCQ6DJFAW5ZU_Q2s4ZmVnaGprbG1ub3BxcnN0dXZ3eHl6MDEyMzQ1Njc4OWFi");
var response = await client.PostAsync(request);
Console.WriteLine("{0}", response.Content);
HttpResponse<String> response = Unirest.post("https://api.1password.com/v1/oauth/introspect")
.header("Authorization", "Basic <encoded-value>")
.header("Content-Type", "application/x-www-form-urlencoded")
.body("token=op_o_c_H3WVOKGN4B7JXQYCQ6DJFAW5ZU_Q2s4ZmVnaGprbG1ub3BxcnN0dXZ3eHl6MDEyMzQ1Njc4OWFi")
.asString();<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.1password.com/v1/oauth/introspect",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => "token=op_o_c_H3WVOKGN4B7JXQYCQ6DJFAW5ZU_Q2s4ZmVnaGprbG1ub3BxcnN0dXZ3eHl6MDEyMzQ1Njc4OWFi",
CURLOPT_HTTPHEADER => [
"Authorization: Basic <encoded-value>",
"Content-Type: application/x-www-form-urlencoded"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}$headers=@{}
$headers.Add("Authorization", "Basic <encoded-value>")
$headers.Add("Content-Type", "application/x-www-form-urlencoded")
$response = Invoke-WebRequest -Uri 'https://api.1password.com/v1/oauth/introspect' -Method POST -Headers $headers -ContentType 'application/x-www-form-urlencoded' -Body 'token=op_o_c_H3WVOKGN4B7JXQYCQ6DJFAW5ZU_Q2s4ZmVnaGprbG1ub3BxcnN0dXZ3eHl6MDEyMzQ1Njc4OWFi'require 'uri'
require 'net/http'
url = URI("https://api.1password.com/v1/oauth/introspect")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Basic <encoded-value>'
request["Content-Type"] = 'application/x-www-form-urlencoded'
request.body = "token=op_o_c_H3WVOKGN4B7JXQYCQ6DJFAW5ZU_Q2s4ZmVnaGprbG1ub3BxcnN0dXZ3eHl6MDEyMzQ1Njc4OWFi"
response = http.request(request)
puts response.read_bodyIntrospect an access token
Check whether an OAuth 2.0 access token for the 1Password Users API is active and retrieve its scopes and expiry time.
curl --request POST \
--url https://api.1password.com/v1/oauth/introspect \
--header 'Authorization: Basic <encoded-value>' \
--header 'Content-Type: application/x-www-form-urlencoded' \
--data token=op_o_c_H3WVOKGN4B7JXQYCQ6DJFAW5ZU_Q2s4ZmVnaGprbG1ub3BxcnN0dXZ3eHl6MDEyMzQ1Njc4OWFiconst encodedParams = new URLSearchParams();
encodedParams.append('token', 'op_o_c_H3WVOKGN4B7JXQYCQ6DJFAW5ZU_Q2s4ZmVnaGprbG1ub3BxcnN0dXZ3eHl6MDEyMzQ1Njc4OWFi');
const url = 'https://api.1password.com/v1/oauth/introspect';
const options = {
method: 'POST',
headers: {
Authorization: 'Basic <encoded-value>',
'Content-Type': 'application/x-www-form-urlencoded'
},
body: encodedParams
};
fetch(url, options)
.then(res => res.json())
.then(json => console.log(json))
.catch(err => console.error(err));import requests
url = "https://api.1password.com/v1/oauth/introspect"
payload = { "token": "op_o_c_H3WVOKGN4B7JXQYCQ6DJFAW5ZU_Q2s4ZmVnaGprbG1ub3BxcnN0dXZ3eHl6MDEyMzQ1Njc4OWFi" }
headers = {
"Authorization": "Basic <encoded-value>",
"Content-Type": "application/x-www-form-urlencoded"
}
response = requests.post(url, data=payload, headers=headers)
print(response.text)package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.1password.com/v1/oauth/introspect"
payload := strings.NewReader("token=op_o_c_H3WVOKGN4B7JXQYCQ6DJFAW5ZU_Q2s4ZmVnaGprbG1ub3BxcnN0dXZ3eHl6MDEyMzQ1Njc4OWFi")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Basic <encoded-value>")
req.Header.Add("Content-Type", "application/x-www-form-urlencoded")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}using RestSharp;
var options = new RestClientOptions("https://api.1password.com/v1/oauth/introspect");
var client = new RestClient(options);
var request = new RestRequest("");
request.AddHeader("Authorization", "Basic <encoded-value>");
request.AddParameter("token", "op_o_c_H3WVOKGN4B7JXQYCQ6DJFAW5ZU_Q2s4ZmVnaGprbG1ub3BxcnN0dXZ3eHl6MDEyMzQ1Njc4OWFi");
var response = await client.PostAsync(request);
Console.WriteLine("{0}", response.Content);
HttpResponse<String> response = Unirest.post("https://api.1password.com/v1/oauth/introspect")
.header("Authorization", "Basic <encoded-value>")
.header("Content-Type", "application/x-www-form-urlencoded")
.body("token=op_o_c_H3WVOKGN4B7JXQYCQ6DJFAW5ZU_Q2s4ZmVnaGprbG1ub3BxcnN0dXZ3eHl6MDEyMzQ1Njc4OWFi")
.asString();<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.1password.com/v1/oauth/introspect",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => "token=op_o_c_H3WVOKGN4B7JXQYCQ6DJFAW5ZU_Q2s4ZmVnaGprbG1ub3BxcnN0dXZ3eHl6MDEyMzQ1Njc4OWFi",
CURLOPT_HTTPHEADER => [
"Authorization: Basic <encoded-value>",
"Content-Type: application/x-www-form-urlencoded"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}$headers=@{}
$headers.Add("Authorization", "Basic <encoded-value>")
$headers.Add("Content-Type", "application/x-www-form-urlencoded")
$response = Invoke-WebRequest -Uri 'https://api.1password.com/v1/oauth/introspect' -Method POST -Headers $headers -ContentType 'application/x-www-form-urlencoded' -Body 'token=op_o_c_H3WVOKGN4B7JXQYCQ6DJFAW5ZU_Q2s4ZmVnaGprbG1ub3BxcnN0dXZ3eHl6MDEyMzQ1Njc4OWFi'require 'uri'
require 'net/http'
url = URI("https://api.1password.com/v1/oauth/introspect")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Basic <encoded-value>'
request["Content-Type"] = 'application/x-www-form-urlencoded'
request.body = "token=op_o_c_H3WVOKGN4B7JXQYCQ6DJFAW5ZU_Q2s4ZmVnaGprbG1ub3BxcnN0dXZ3eHl6MDEyMzQ1Njc4OWFi"
response = http.request(request)
puts response.read_body200 OK for an active token. If a token has expired, been revoked, is unknown, or was issued to a different OAuth application, the response also returns 200 OK, but with "active": false and no other fields, so the response doesn’t reveal anything about tokens that don’t belong to your application.
If the token parameter isn’t included in the request, the response returns a 400 Bad Request error.
This endpoint is rate limited. Requests that exceed the limit return a 429 Too Many Requests error.
Learn more about errors and rate limits.Authorizations
HTTP Basic authentication with the OAuth application's client credentials: the client ID as the username and the client secret as the password, joined with a colon and base64-encoded (Authorization: Basic <base64(client_id:client_secret)>). Tools such as curl encode the credentials for you when you pass them with --user "<client_id>:<client_secret>". Alternatively, send the credentials as the client_id and client_secret form fields in the request body. Don't use both methods in the same request.
Body
The access token to introspect.
The client ID of the OAuth application. Use together with client_secret as an alternative to HTTP Basic authentication.
"H3WVOKGN4B7JXQYCQ6DJFAW5ZU"
The client secret of the OAuth application. Use together with client_id as an alternative to HTTP Basic authentication.
A hint about the type of token. Optional; only access tokens are issued.
access_token Response
The token's introspection result.
Whether the token is currently active. false for tokens that are expired, revoked, unknown, or issued to a different OAuth application; the remaining fields are omitted in that case.
The scopes granted to the token, separated by spaces.
"users.view users.suspend users.reactivate"
The client ID of the OAuth application the token was issued to.
"H3WVOKGN4B7JXQYCQ6DJFAW5ZU"
The subject of the token. For client credentials tokens, this is the client ID.
"H3WVOKGN4B7JXQYCQ6DJFAW5ZU"
The token type. Always Bearer for active tokens.
"Bearer"
When the token expires, as a Unix timestamp in seconds.
1760000900
When the token was issued, as a Unix timestamp in seconds.
1760000000
Was this page helpful?