Tokens
Inspect Token
Return the namespace, grants, and expiry of the token used to authenticate the request.
GET https://api.rivet.dev/auth/tokens/inspect
Examples
curl "https://api.rivet.dev/auth/tokens/inspect" \
-H "Authorization: Bearer $RIVET_TOKEN"
const endpoint = "https://api.rivet.dev";
const token = process.env.RIVET_TOKEN ?? "";
// Inspect reports on the token used to authenticate the request itself.
const response = await fetch(`${endpoint}/auth/tokens/inspect`, {
headers: { Authorization: `Bearer ${token}` },
});
const { namespace_id, subject, grants, expires_ts } = await response.json();
console.log(namespace_id, subject, grants, new Date(expires_ts));
export {};
Authentication
Send your namespace token as a bearer token in the Authorization header. Every control plane request also requires the namespace query parameter. See Authentication.
Responses
200
| Field | Type | Description |
|---|---|---|
expires_ts | integer | When the token expires, in Unix milliseconds. |
grants | object[] | Permissions the token carries. |
grants[].operations | ("read" | "update" | "list" | "create" | "delete")[] | Operations the token may perform on the target. |
grants[].resource | "namespace" | "actor" | "runner" | "runner_config" | "datacenter" | "actor_gateway" | "actor_kv" | Resource type the grant applies to. |
grants[].target | "any" | object | "any" for every resource of this type, or { "id": "..." } for one resource. |
issued_ts | integer | When the token was issued, in Unix milliseconds. |
namespace_id | string | ID of the namespace the token is scoped to. |
subject | string | null | Subject attached to the token, if any. |
{
"expires_ts": 1700000000000,
"grants": [
{
"operations": [
"read"
],
"resource": "namespace",
"target": "any"
}
],
"issued_ts": 1700000000000,
"namespace_id": "00000000-0000-0000-0000-000000000000",
"subject": null
}