Skip to main content
IAMRoadmapIAMRoadmap

OAuth Introspection Tester

Build and test RFC 7662 Token Introspection requests

Introspection Request

Client Authentication

CORS Limitation

Browser security prevents direct API calls. Copy the generated code and run it in your terminal or server.

Generated Code

Enter endpoint and token to generate code

Expected Response

Active Token

{
  "active": true,
  "client_id": "my-client",
  "username": "[email protected]",
  "scope": "openid profile email",
  "sub": "user-123",
  "aud": "https://api.example.com",
  "iss": "https://auth.example.com",
  "exp": 1704067200,
  "iat": 1704063600
}

Inactive/Expired Token

{
  "active": false
}

Common Endpoints

  • Auth0:https://{domain}/oauth/introspect
  • Okta:https://{domain}/oauth2/v1/introspect
  • Keycloak:https://{domain}/realms/{realm}/protocol/openid-connect/token/introspect
  • PingFederate:https://{domain}/as/introspect.oauth2
Learn More

About Token Introspection (RFC 7662)

  • •Allows resource servers to query the authorization server about token validity
  • •Returns active: true/false indicating token status
  • •Supports opaque tokens that can't be decoded client-side
  • •Requires client authentication (client_secret_basic or client_secret_post)

Introspection in IAM

  • •Token Validation – Check if access token is still valid
  • •Opaque Tokens – Validate non-JWT tokens
  • •Revocation Check – Detect revoked tokens
  • •Claims Retrieval – Get token metadata server-side