Skip to main content
GET
Get access token by value

Authorizations

Authorization
string
header
required

Path Parameters

token
string
required

Response

Successful response

Access-token metadata returned by POST /v4/tokens, POST /v4/tokens/openid-connect/authorization-code-flow, GET /v4/tokens, GET /v4/tokens/{token}, and PUT /v4/tokens/exchange/{token}. Pass access_token in the Authorization header (Bearer ...) on subsequent requests.

access_token
string

Token string. Send as Authorization: Bearer <access_token> on subsequent requests, or as the access_token query parameter / extole_token cookie.

client_id
string

Stable Extole identifier for the client (tenant) this token authenticates against.

expires_in
integer<int64>

Seconds until this token expires. Once expired, requests using it return 401 invalid_access_token; rotate via PUT /v4/tokens/exchange/{token} before expiry to keep long-lived integrations alive.

identity_id
string

Stable Extole identifier for the identity (user, managed identity, or resource) that this token represents.

person_id
string
deprecated

Deprecated alias for identity_id. New integrations should use identity_id.

scopes
enum<string>[]

Authorization scopes granted to this token. Determines which API operations the token may invoke.

Authorization scopes granted to this token. Determines which API operations the token may invoke.

Available options:
BACKEND,
CLIENT_ADMIN,
CLIENT_REPORT_DOWNLOAD,
CLIENT_SUPERUSER,
ONE_TIME,
PASSWORD_RESET,
UPDATE_PROFILE,
USER_SUPPORT,
VERIFIED_CONSUMER
type
enum<string>

Authentication shape backing the token. USER represents a human dashboard user, MANAGED an OAuth-style managed identity, and RESOURCE a scoped per-resource token.

Available options:
MANAGED,
RESOURCE,
USER