Sessions
Validate Session
Validate a session for a given access token. This will ensure both that the token signature is valid and that the token has not been revoked.
POST
/
sessions
/
validate
Validate session
curl --request POST \
--url https://api.authsignal.com/v1/sessions/validate \
--header 'Authorization: Basic <encoded-value>' \
--header 'Content-Type: application/json' \
--data '
{
"accessToken": "eyJhbGciOiJ...",
"clientIds": [
"64818035-68c3-4087-a449-bdd176a166c4"
]
}
'import requests
url = "https://api.authsignal.com/v1/sessions/validate"
payload = {
"accessToken": "eyJhbGciOiJ...",
"clientIds": ["64818035-68c3-4087-a449-bdd176a166c4"]
}
headers = {
"Authorization": "Basic <encoded-value>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Basic <encoded-value>', 'Content-Type': 'application/json'},
body: JSON.stringify({
accessToken: 'eyJhbGciOiJ...',
clientIds: ['64818035-68c3-4087-a449-bdd176a166c4']
})
};
fetch('https://api.authsignal.com/v1/sessions/validate', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.authsignal.com/v1/sessions/validate",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'accessToken' => 'eyJhbGciOiJ...',
'clientIds' => [
'64818035-68c3-4087-a449-bdd176a166c4'
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Basic <encoded-value>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.authsignal.com/v1/sessions/validate"
payload := strings.NewReader("{\n \"accessToken\": \"eyJhbGciOiJ...\",\n \"clientIds\": [\n \"64818035-68c3-4087-a449-bdd176a166c4\"\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Basic <encoded-value>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.authsignal.com/v1/sessions/validate")
.header("Authorization", "Basic <encoded-value>")
.header("Content-Type", "application/json")
.body("{\n \"accessToken\": \"eyJhbGciOiJ...\",\n \"clientIds\": [\n \"64818035-68c3-4087-a449-bdd176a166c4\"\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.authsignal.com/v1/sessions/validate")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Basic <encoded-value>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"accessToken\": \"eyJhbGciOiJ...\",\n \"clientIds\": [\n \"64818035-68c3-4087-a449-bdd176a166c4\"\n ]\n}"
response = http.request(request)
puts response.read_body{
"user": {},
"expiresAt": 123
}{
"error": "<string>",
"errorDescription": "<string>"
}{
"error": "<string>",
"errorDescription": "<string>"
}Authorizations
Use your Authsignal Server API secret key as the username and leave the password empty. The secret key can be found in the API Keys section of the Authsignal Portal settings page.
Body
application/json
Response
OK
A JSON object containing user claims.
The token expiry as a Unix timestamp in seconds.
The verification method which was used to create the session.
Available options:
SMS, AUTHENTICATOR_APP, EMAIL_MAGIC_LINK, EMAIL_OTP, PUSH, DEVICE, SECURITY_KEY, PASSKEY, VERIFF, IPROOV, PALM_BIOMETRICS_RR, IDVERSE Was this page helpful?
⌘I
Validate session
curl --request POST \
--url https://api.authsignal.com/v1/sessions/validate \
--header 'Authorization: Basic <encoded-value>' \
--header 'Content-Type: application/json' \
--data '
{
"accessToken": "eyJhbGciOiJ...",
"clientIds": [
"64818035-68c3-4087-a449-bdd176a166c4"
]
}
'import requests
url = "https://api.authsignal.com/v1/sessions/validate"
payload = {
"accessToken": "eyJhbGciOiJ...",
"clientIds": ["64818035-68c3-4087-a449-bdd176a166c4"]
}
headers = {
"Authorization": "Basic <encoded-value>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Basic <encoded-value>', 'Content-Type': 'application/json'},
body: JSON.stringify({
accessToken: 'eyJhbGciOiJ...',
clientIds: ['64818035-68c3-4087-a449-bdd176a166c4']
})
};
fetch('https://api.authsignal.com/v1/sessions/validate', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.authsignal.com/v1/sessions/validate",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'accessToken' => 'eyJhbGciOiJ...',
'clientIds' => [
'64818035-68c3-4087-a449-bdd176a166c4'
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Basic <encoded-value>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.authsignal.com/v1/sessions/validate"
payload := strings.NewReader("{\n \"accessToken\": \"eyJhbGciOiJ...\",\n \"clientIds\": [\n \"64818035-68c3-4087-a449-bdd176a166c4\"\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Basic <encoded-value>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.authsignal.com/v1/sessions/validate")
.header("Authorization", "Basic <encoded-value>")
.header("Content-Type", "application/json")
.body("{\n \"accessToken\": \"eyJhbGciOiJ...\",\n \"clientIds\": [\n \"64818035-68c3-4087-a449-bdd176a166c4\"\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.authsignal.com/v1/sessions/validate")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Basic <encoded-value>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"accessToken\": \"eyJhbGciOiJ...\",\n \"clientIds\": [\n \"64818035-68c3-4087-a449-bdd176a166c4\"\n ]\n}"
response = http.request(request)
puts response.read_body{
"user": {},
"expiresAt": 123
}{
"error": "<string>",
"errorDescription": "<string>"
}{
"error": "<string>",
"errorDescription": "<string>"
}
