openapi: 3.0.3 info: title: Stack Exchange Access Tokens API description: 'Public, read-mostly HTTP/JSON API spanning all 180+ Stack Exchange sites (Stack Overflow, Server Fault, Super User, Ask Ubuntu, Stats, Math Overflow, ...). All method families live under a single base URL with a uniform wrapper (`items`, `has_more`, `page`, `quota_max`, `quota_remaining`, `backoff`). Read access is unauthenticated. Write methods require OAuth 2.0 with the appropriate scopes (`write_access`, `private_info`, `no_expiry`). Most paths take a required `site` query parameter naming the target Q&A community (`stackoverflow`, `serverfault`, `superuser`, ...). Use `/sites` to enumerate the network. ' version: '2.3' termsOfService: https://stackoverflow.com/legal/api-terms-of-use contact: name: Stack Exchange API url: https://api.stackexchange.com/ license: name: Creative Commons BY-SA 4.0 (content) / API Terms of Use url: https://stackoverflow.com/legal/api-terms-of-use x-generated-from: documentation x-last-validated: '2026-05-29' servers: - url: https://api.stackexchange.com/2.3 description: Stack Exchange API v2.3 production endpoint security: - apiKey: [] tags: - name: Access Tokens description: OAuth access token introspection and invalidation. paths: /access-tokens/{accessTokens}/invalidate: get: tags: - Access Tokens operationId: invalidateAccessTokens summary: Stack Exchange Invalidate Access Tokens description: Invalidate the given access tokens. Requires the app's `key`. parameters: - name: accessTokens in: path required: true description: Up to 100 semicolon-delimited access tokens to invalidate. schema: type: string - $ref: '#/components/parameters/Key' - $ref: '#/components/parameters/Filter' responses: '200': description: A page of access tokens with their invalidation status. content: application/json: schema: $ref: '#/components/schemas/AccessTokensResponse' x-microcks-operation: delay: 0 dispatcher: FALLBACK /access-tokens/{accessTokens}/read: get: tags: - Access Tokens operationId: readAccessTokens summary: Stack Exchange Read Access Tokens description: Inspect the given access tokens (scopes, expiry, account id). parameters: - name: accessTokens in: path required: true description: Up to 100 semicolon-delimited access tokens to inspect. schema: type: string - $ref: '#/components/parameters/Key' - $ref: '#/components/parameters/Filter' responses: '200': description: A page of access tokens. content: application/json: schema: $ref: '#/components/schemas/AccessTokensResponse' x-microcks-operation: delay: 0 dispatcher: FALLBACK /apps/{accessTokens}/de-authenticate: get: tags: - Access Tokens operationId: deauthenticateApp summary: Stack Exchange De-Authenticate App description: De-authenticate the named app for the holder(s) of the given access tokens. parameters: - name: accessTokens in: path required: true schema: type: string - $ref: '#/components/parameters/Key' - $ref: '#/components/parameters/Filter' responses: '200': description: A page of access tokens. content: application/json: schema: $ref: '#/components/schemas/AccessTokensResponse' x-microcks-operation: delay: 0 dispatcher: FALLBACK components: parameters: Key: name: key in: query required: false description: App key from stackapps.com. Raises the daily quota to 10,000/IP. schema: type: string example: example_app_key_abcdef Filter: name: filter in: query required: false description: Custom response filter id created via /filters/create. schema: type: string example: default schemas: AccessToken: type: object description: An OAuth access token, returned by the access-token endpoints. properties: access_token: type: string expires_on_date: type: integer format: int64 account_id: type: integer format: int64 scope: type: array items: type: string AccessTokensResponse: allOf: - $ref: '#/components/schemas/Wrapper' - type: object properties: items: type: array items: $ref: '#/components/schemas/AccessToken' Wrapper: type: object description: Common envelope returned by every Stack Exchange API method. properties: backoff: type: integer description: Seconds the client MUST wait before re-querying this same method. Returned when the API has identified the consumer as expensive. example: 0 error_id: type: integer description: Numeric error code when the response is an error. error_message: type: string description: Human-readable error message. error_name: type: string description: Stable error name (e.g. `throttle_violation`). has_more: type: boolean description: True when more pages exist past the returned `page`. example: true page: type: integer description: Page number echoed from the request. example: 1 page_size: type: integer description: Page size echoed from the request. example: 30 quota_max: type: integer description: Daily quota for the IP/key combination. example: 10000 quota_remaining: type: integer description: Quota left after this request. example: 9999 total: type: integer description: Total count when the consumer requested it via filter. type: type: string description: Type name of the items returned. required: - has_more - quota_max - quota_remaining securitySchemes: oauth2: type: oauth2 description: 'OAuth 2.0 explicit or implicit flow. Apps register on stackapps.com. Read methods do not require auth; write methods require `write_access`. `private_info` is needed for /me/notifications, /me/inbox, and similar private surfaces. `no_expiry` issues tokens that never expire. ' flows: authorizationCode: authorizationUrl: https://stackoverflow.com/oauth tokenUrl: https://stackoverflow.com/oauth/access_token scopes: read_inbox: Access the authenticated user's inbox. no_expiry: Issue a token that never expires. write_access: Vote, post, comment, flag, accept on the user's behalf. private_info: Access endpoints that return personal information. apiKey: type: apiKey in: query name: key description: 'Optional app key. Sending a key raises the daily quota from 300 to 10,000 requests per IP and is the recommended default for any non-trivial client. '