> ## Documentation Index
> Fetch the complete documentation index at: https://docs.capedigital.co.ke/llms.txt
> Use this file to discover all available pages before exploring further.

# Introspect a profile token (service-to-service)

> Optional service-to-service validation of a profile token.

Redundant with the JWKS endpoint (downstream can validate offline); kept as a
convenience/debug endpoint for services that prefer a remote check.



## OpenAPI

````yaml /openapi/user.yaml post /api/v1/auth/profiles/token/introspect
openapi: 3.0.3
info:
  title: CapeMedia User Service API
  version: 1.0.0
  description: |2-

        **CapeMedia User Service API** - Comprehensive user service and management system.

        ## Authentication
        This API uses **JWT Bearer tokens** for authentication.

        1. Login via `/api/v1/auth/login` to obtain tokens
        2. Include the access token in the `Authorization` header: `Bearer <access_token>`
        3. Refresh expired tokens via `/api/v1/auth/refresh-token`

        ## Versioning
        The API uses URL path versioning (e.g., `/api/v1/`, `/api/v2/`).
        Current version: **v1**
        
  contact:
    name: API Support
    email: support@capemedia.co.ke
  license:
    name: Cape Media
servers:
  - url: https://api.diginacape.co.ke/acl
    description: Production
  - url: http://localhost:8000
    description: Local
security: []
paths:
  /api/v1/auth/profiles/token/introspect:
    post:
      tags:
        - Profiles
      summary: Introspect a profile token (service-to-service)
      description: >-
        Optional service-to-service validation of a profile token.


        Redundant with the JWKS endpoint (downstream can validate offline); kept
        as a

        convenience/debug endpoint for services that prefer a remote check.
      operationId: profiles_token_introspect
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ProfileTokenIntrospectRequestRequest'
          application/x-www-form-urlencoded:
            schema:
              $ref: '#/components/schemas/ProfileTokenIntrospectRequestRequest'
          multipart/form-data:
            schema:
              $ref: '#/components/schemas/ProfileTokenIntrospectRequestRequest'
        required: true
      responses:
        '200':
          content:
            application/json:
              schema:
                type: object
                additionalProperties: {}
          description: Decoded claims
      security:
        - bearerAuth: []
components:
  schemas:
    ProfileTokenIntrospectRequestRequest:
      type: object
      properties:
        token:
          type: string
          minLength: 1
      required:
        - token
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: 'Enter your JWT token in the format: Bearer <token>'

````