Get Token Info
GET/v1/open-api/token/info
Introspect the calling X-Open-Api-Token: which Open API application issued it, which
company it belongs to, when it expires and what it is allowed to do. Use it to bind a
token to a company on your side, to warn before an expiry, and to check the granted
permissions before calling a resource endpoint.
The company's timeZone is the zone every *Timestamp field (epoch seconds) in this API
is meant to be rendered in.
Neither the token nor its hash is returned.
Requires no specific grant — any valid, non-expired token is accepted.
Responses
- 200
- 401
- 429
Information about the calling token.
Invalid, revoked or expired token (401) — also returned when the connection was
revoked or the company is blocked.
Produced by the authentication filter, so the body is a reduced envelope: no
error, no requestId, and errors is null rather than []. Every cause yields the
same fixed English message.
Rate limit of 60 requests/minute exceeded (429). Like 401, this comes from the
authentication filter: reduced envelope, fixed English message, no error object and no
Retry-After header.