openapi: 3.2.0 info: title: Janssen Authorization Server Token Introspection API description: Janssen Authorization Server - OAuth 2.0 server; OpenID Connect Provider (OP) & UMA Authorization Server (AS) contact: name: Contact url: https://github.com/JanssenProject/jans/discussions license: name: License url: https://github.com/JanssenProject/jans/blob/main/LICENSE version: OAS Version servers: - url: https://jans.local.io/jans-auth tags: - name: Token Introspection paths: /restv1/rpt/status: get: tags: - Token Introspection summary: The Introspection OAuth 2 Endpoint for RPT description: The Introspection OAuth 2 Endpoint for RPT. operationId: get-rpt-status parameters: - name: Authorization in: header required: true schema: type: string - name: token in: query required: true schema: type: string - name: token_type_hint in: query schema: type: string responses: 200: description: OK content: application/json: schema: title: RptIntrospectionResponse type: object required: - active - permissions - resource_id - resource_scopes properties: active: type: boolean description: Boolean indicator of whether or not the presented token is currently active. exp: type: integer description: Integer timestamp, in seconds since January 1 1970 UTC, indicating when this token will expire. format: int64 example: 1256953732 iat: type: integer description: Integer timestamp, measured in the number of seconds since January 1 1970 UTC, indicating when this permission was originally issued. example: 1256953732 clientId: type: string description: Client id used to obtain RPT. sub: type: string description: Subject of the token. Usually a machine-readable identifier of the resource owner who authorized this token. aud: type: string description: Service-specific string identifier or list of string identifiers representing the intended audience for this token. permissions: type: array items: type: object description: List of UmaPermission granted to RPT. A permission is (requested or granted) authorized access to a particular resource with some number of scopes bound to that resource. required: - resource_id - resource_scopes properties: resource_id: type: string description: A string that uniquely identifies the protected resource, access to which has been granted to this client on behalf of this requesting party. The identifier MUST correspond to a resource that was previously registered as protected. resource_scopes: type: array description: An array referencing zero or more strings representing scopes to which access was granted for this resource. Each string MUST correspond to a scope that was registered by this resource server for the referenced resource. items: type: string exp: type: integer description: Integer timestamp, measured in the number of seconds since January 1 1970 UTC, indicating when this permission will expire. If the token-level exp value pre-dates a permission-level exp value, the token-level value takes precedence. iat: type: integer description: Integer timestamp, measured in the number of seconds since January 1 1970 UTC, indicating when this permission was originally issued. If the token-level iat value post-dates a permission-level iat value, the token-level value takes precedence. nbf: type: integer description: Integer timestamp, measured in the number of seconds since January 1 1970 UTC, indicating the time before which this permission is not valid. If the token-level nbf value post-dates a permission-level nbf value, the token-level value takes precedence. pct_claims: type: object additionalProperties: type: string description: PCT token claims. iss: type: string description: String representing the issuer of this token, as defined in JWT [RFC7519]. jti: type: string description: String identifier for the token, as defined in JWT [RFC7519]. nbf: type: integer description: Integer timestamp, measured in the number of seconds since January 1 1970 UTC, indicating the time before which this permission is not valid. resource_id: type: string description: Resource ID. resource_scopes: type: array items: type: string 405: description: Introspection of RPT is not allowed. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' 500: description: Invalid parameters provided to endpoint. content: application/json: schema: type: object required: - error - error_description properties: error: type: string format: enum example: - server_error error_description: type: string details: type: string post: tags: - Token Introspection summary: The Introspection OAuth 2 Endpoint for RPT description: The Introspection OAuth 2 Endpoint for RPT. operationId: post-rpt-status parameters: - name: Authorization in: header required: true description: Client Authorization details that contains the access token along with other details. schema: type: string requestBody: content: application/x-www-form-urlencoded: schema: type: object required: - token properties: token: type: string description: Client access token. token_type_hint: type: string description: ID Token previously issued by the Authorization Server being passed as a hint about the End-User. responses: 200: description: OK content: application/json: schema: title: RptIntrospectionResponse type: object required: - active - permissions - resource_id - resource_scopes properties: active: type: boolean description: Boolean indicator of whether or not the presented token is currently active. exp: type: integer description: Integer timestamp, in seconds since January 1 1970 UTC, indicating when this token will expire. format: int64 example: 1256953732 iat: type: integer description: Integer timestamp, measured in the number of seconds since January 1 1970 UTC, indicating when this permission was originally issued. example: 1256953732 clientId: type: string description: Client id used to obtain RPT. sub: type: string description: Subject of the token. Usually a machine-readable identifier of the resource owner who authorized this token. aud: type: string description: Service-specific string identifier or list of string identifiers representing the intended audience for this token. permissions: type: array items: type: object description: List of UmaPermission granted to RPT. A permission is (requested or granted) authorized access to a particular resource with some number of scopes bound to that resource. required: - resource_id - resource_scopes properties: resource_id: type: string description: A string that uniquely identifies the protected resource, access to which has been granted to this client on behalf of this requesting party. The identifier MUST correspond to a resource that was previously registered as protected. resource_scopes: type: array description: An array referencing zero or more strings representing scopes to which access was granted for this resource. Each string MUST correspond to a scope that was registered by this resource server for the referenced resource. items: type: string exp: type: integer description: Integer timestamp, measured in the number of seconds since January 1 1970 UTC, indicating when this permission will expire. If the token-level exp value pre-dates a permission-level exp value, the token-level value takes precedence. iat: type: integer description: Integer timestamp, measured in the number of seconds since January 1 1970 UTC, indicating when this permission was originally issued. If the token-level iat value post-dates a permission-level iat value, the token-level value takes precedence. nbf: type: integer description: Integer timestamp, measured in the number of seconds since January 1 1970 UTC, indicating the time before which this permission is not valid. If the token-level nbf value post-dates a permission-level nbf value, the token-level value takes precedence. pct_claims: type: object additionalProperties: type: string description: PCT token claims. example: '{name:["John"]}' iss: type: string description: String representing the issuer of this token, as defined in JWT [RFC7519]. jti: type: string description: String identifier for the token, as defined in JWT [RFC7519]. nbf: type: integer description: Integer timestamp, measured in the number of seconds since January 1 1970 UTC, indicating the time before which this permission is not valid. resource_id: type: string description: Resource ID. resource_scopes: type: array items: type: string 405: description: Introspection of RPT is not allowed. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' 500: description: Invalid parameters provided to endpoint. content: application/json: schema: type: object required: - error - error_description properties: error: type: string format: enum example: - server_error error_description: type: string details: type: string components: schemas: ErrorResponse: required: - error - error_description type: object properties: error: type: string error_description: type: string details: type: string securitySchemes: bearer: type: http scheme: bearer