> ## Documentation Index
> Fetch the complete documentation index at: https://devs.izap.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Introspect the presented credential

> Resolves the credential on the request to its principal, or returns `401` if it is not valid. Accepts a JWT, a session cookie, a personal access token or a business API key — use it to confirm that a token is still good and who it belongs to.



## OpenAPI

````yaml /api-reference/openapi.json get /api/v1/auth/token/introspect
openapi: 3.1.0
info:
  contact:
    email: suporte@izap.ai
    name: iZap API Support
  description: Public REST API for the iZap WhatsApp business messaging platform.
  license:
    name: MIT
    url: https://opensource.org/licenses/MIT
  title: iZap API
  version: v1
servers:
  - description: Production
    url: https://api.izap.ai
  - description: Staging
    url: https://api-staging.izap.ai
security: []
tags:
  - description: >-
      Personal access tokens for calling this API, plus introspection of the
      token presented on a request.
    name: api-tokens
  - description: >-
      Create a business, read and update its profile, and manage its opening
      hours.
    name: businesses
  - description: >-
      Reusable images belonging to the caller's business, referenced when
      composing messages.
    name: business-library
  - description: Product catalog menus a business publishes to its customers.
    name: menus
  - description: >-
      Provision and inspect the WhatsApp Cloud API numbers attached to a
      business: registration, WABA details, per-number assistant binding and
      catalog sends.
    name: whatsapp-cloud
  - description: >-
      Conversation lifecycle — list, create and delete chats, and control read,
      snooze, status and AI pause state.
    name: chats
  - description: >-
      Read a conversation's messages, send free-form or template replies, and
      upload attachments.
    name: messages
  - description: >-
      Manage WhatsApp message templates: draft them locally, submit them to Meta
      for review and sync approval status back.
    name: whatsapp-templates
  - description: >-
      Bulk template sends. A transmission is previewed into a draft, then
      confirmed or cancelled — confirming dispatches to real recipients.
    name: transmissions
  - description: >-
      Register URLs that receive signed event deliveries when something happens
      in a business, rotate their signing secrets, and replay an individual
      delivery.
    name: webhooks
  - description: >-
      Server-rendered order visualisation page for a business slug, behind HTTP
      Basic auth.
    name: orders
paths:
  /api/v1/auth/token/introspect:
    get:
      tags:
        - api-tokens
      summary: Introspect the presented credential
      description: >-
        Resolves the credential on the request to its principal, or returns
        `401` if it is not valid. Accepts a JWT, a session cookie, a personal
        access token or a business API key — use it to confirm that a token is
        still good and who it belongs to.
      operationId: introspectToken
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PrincipalResponse'
          description: Successful Response
        '401':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
          description: Missing or invalid credentials.
        '403':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
          description: The credential is valid but not authorized for this action.
        default:
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
          description: Unexpected error.
      security:
        - bearerAuth: []
components:
  schemas:
    PrincipalResponse:
      description: 'Introspection result: who the presented credential authenticates as.'
      properties:
        business_id:
          anyOf:
            - format: uuid
              type: string
            - type: 'null'
          description: Set when authenticated as a business API key.
          title: Business Id
        kind:
          description: '''user'' or ''business_api_key''.'
          title: Kind
          type: string
        token_id:
          anyOf:
            - format: uuid
              type: string
            - type: 'null'
          description: Id of the token row used, if any.
          title: Token Id
        user_id:
          anyOf:
            - format: uuid
              type: string
            - type: 'null'
          description: Set when authenticated as a user.
          title: User Id
      required:
        - kind
      title: PrincipalResponse
      type: object
    ApiError:
      description: >-
        The response body of a handled API error.


        ``detail`` is either a plain string (FastAPI's default for an

        ``HTTPException`` raised with a string, and for the ``default``
        fastapi-users

        messages like ``"Not authenticated"``) or the structured

        :class:`ApiErrorDetail` object described above. ``code`` is present only
        on

        the top-level shape ``aizap.core.exceptions.AppException`` produces for
        its

        own 5xx responses (``"INTERNAL_ERROR"`` / ``"DB_ERROR"``); it does not

        duplicate the ``code`` nested inside a structured ``detail``.
      properties:
        code:
          anyOf:
            - type: string
            - type: 'null'
          default: null
          title: Code
        detail:
          anyOf:
            - type: string
            - $ref: '#/components/schemas/ApiErrorDetail'
          title: Detail
      required:
        - detail
      title: ApiError
      type: object
    ApiErrorDetail:
      additionalProperties: true
      description: |-
        The structured ``detail`` object some error responses carry.

        Several handlers (the REST API plan gate, the free-tier limits, the
        webhooks entitlement gate, the closed customer-service window) raise
        ``HTTPException(detail={"code": ..., "message": ..., ...})`` — a fixed
        ``code``/``message`` pair plus extra fields specific to that error.
        ``extra="allow"`` keeps those fields in the documented shape instead of
        dropping them.
      properties:
        code:
          title: Code
          type: string
        message:
          title: Message
          type: string
      required:
        - code
        - message
      title: ApiErrorDetail
      type: object
  securitySchemes:
    bearerAuth:
      description: >-
        Personal access token (izap_pat_…) sent as Authorization: Bearer
        <token>; dashboard session JWTs are also accepted.
      scheme: bearer
      type: http

````