Skip to main content
GET
/
token
/
inspect
Inspect
curl --request GET \
  --url https://{cluster}.cognitedata.com/api/v1/token/inspect \
  --header 'Authorization: Bearer <token>'
{
  "subject": "<string>",
  "projects": [
    {
      "projectUrlName": "<string>",
      "groups": [
        123
      ]
    }
  ],
  "capabilities": [
    {
      "groupsAcl": {
        "actions": [
          "LIST"
        ],
        "scope": {
          "all": {}
        }
      },
      "projectScope": {
        "allProjects": {}
      }
    }
  ]
}

Authorizations

Authorization
string
header
required

Access token issued by the CDF project's configured identity provider. Access token must be an OpenID Connect token, and the project must be configured to accept OpenID Connect tokens. Use a header key of 'Authorization' with a value of 'Bearer $accesstoken'. The token can be obtained through any flow supported by the identity provider.

Response

Ok response

subject
string
required

Subject (sub claim) of JWT

projects
projects · object[]
required
capabilities
(Groups Capability · object | Assets Capability · object | Events Capability · object | Files Capability · object | Projects Capability · object | Security Category Capability · object | Raw Capability · object | TimeSeries Capability · object | Threed Capability · object | Sequences Capability · object | Labels Capability · object | Analytics Capability · object | Digital Twin Capability · object | Data Modeling Schema Capability · object | Data Modeling Instances Capability · object | Industrial Log Analytics Instances Capability · object | Relationships Capability · object | Datasets Capability · object | Seismic Capability · object | Types Capability · object | Functions Capability · object | Extraction Pipelines Capability · object | Extraction Pipeline Runs Capability · object | Limits Capability · object)[]
required
Last modified on April 23, 2026