OAuth Introspection Tester
Build and test RFC 7662 Token Introspection requests
Introspection Request
Client Authentication
CORS Limitation
Browser security prevents direct API calls. Copy the generated code and run it in your terminal or server.
Generated Code
Enter endpoint and token to generate code
Expected Response
Active Token
{
"active": true,
"client_id": "my-client",
"username": "[email protected]",
"scope": "openid profile email",
"sub": "user-123",
"aud": "https://api.example.com",
"iss": "https://auth.example.com",
"exp": 1704067200,
"iat": 1704063600
}Inactive/Expired Token
{
"active": false
}Common Endpoints
- Auth0:
https://{domain}/oauth/introspect - Okta:
https://{domain}/oauth2/v1/introspect - Keycloak:
https://{domain}/realms/{realm}/protocol/openid-connect/token/introspect - PingFederate:
https://{domain}/as/introspect.oauth2
Learn More
About Token Introspection (RFC 7662)
- •Allows resource servers to query the authorization server about token validity
- •Returns
active: true/falseindicating token status - •Supports opaque tokens that can't be decoded client-side
- •Requires client authentication (client_secret_basic or client_secret_post)
Introspection in IAM
- •Token Validation – Check if access token is still valid
- •Opaque Tokens – Validate non-JWT tokens
- •Revocation Check – Detect revoked tokens
- •Claims Retrieval – Get token metadata server-side