---
id: token-verification-and-authorisation
title: "Token Verification and Authorisation"
description: "The Token Verification and Authorisation endpoint for an organisation in  regards to a Data Marketplace. An Access Token issued as a result of a Pull-Data request can be verified here, and an authorisation decision can be made  against the requested resource (defined by OpenAPI method and path). The  resource is checked against the OpenAPI specification of the underlying  Data Agreement within the Data Disclosure Agreement Record's Template  connected to the Access Token."
sidebar_label: "Token Verification and Authorisation"
hide_title: true
hide_table_of_contents: true
api: eJztV81uGzcQfpUBL02AleQ46UUIgjp22jppGiNWmoNjwCNytMuYS25IrmTF0K1P0kfrkxTDXUm7ktM6Oba92CuS88NvvvnhrVAUpNdV1M6KsZgUBBN3TRZ+I69nWiJvAFoFR3UsnNehWSGrKqdthJnzgBacz9GuN7UF8JSjVwGiA4QTjAiv0V9TrAxKGsKRhSMpKYTWnA6hJgUYAMFTqE0ENwOEs9qYQRL39KmmEEGihSnBPPlHCgrylCUP0QL2nFQkdeCPVqZERQCYo7YhQixorZQUG3W1lwQPFM20JQXTJbypyB6dnUJJsXAqGakwFg+HwEBtZXQAWZC85ht0tK/FQ0VyC6abpc3aKvJmqW0ODT5HuScqyUZY6Fhom06lnRMdpHGh9tQ59Jak8+q7ABMqK4ORAKSzliTfJrok3YV4+MGKTLQXfu7UUoxvhXQ2ko38iVVlWhdHHwOz4VYEWVCJ/BWXFYmxcNOPJKPIROVdRT5qCkk22UlmOodD9NrmIruDYy/fT/rxj64X1BTONpakxCoTRYzV6xSG+1n4eTI5g0agVX7vCLE5DvP9DPHJb7FAN9LUijjAxwZD2G5uzU6dM3tG3xcUC/Jss9WRDClmiuxpgpl3ZctzTqmkaob8NZ6hCbR149QqPdeqRhO+0b7eavgKuycknSJ1bFCX32pZNTr48rq8h/FVkwbakxLjix55ezxrWXC5WjUioXI2NIQ/PDjgf333WkLHROh5t35uPLl3vjlLb2ZifLGfeV3X1/nCd9znUSY6MUkwdLG+XGX3Vu4J2cPLVYvFk4NHX1U9umrJe+ePnSKRNd8nHRAvs3+oNFvpLVe0jZSTZ303WFaGxPjJwcHqDvV3JPRGRDxHBdpWdYQKPZYUyYtVc99+nN/ZtjR9TuAUhIo8e8dHv2+Y8R+F5tRG8hYNBPJz8pDM7GG0/SWOG5wGk2T7jo5zhzd7gO650dUKjTWRvA0ka6/jMmXWUaVfEX9erhhczAMHoT/nnKd7MPhl23xE5UJc14axGM0fj/iyWtKIc3AQKpQ0mqPRCiMNmuoi2DRrCsly39sTKl0LmMhE7Y0YpzIUxqORotINsNJDnXu0caid4LztKziPmPMc8QUdodneVXO5heOcUW9YtAZlEwBsFriYsM4GzExYLHm3RevzuuLsVMSzU7imZWrlZGMbtGZ6mqOpaT0MXfX0XLUxg7IOkRtr5Wmmb0ilyQiuGh/hCh5YF5seED1qkzBg+B9mQMN8uKN2DK3g06WrPcMxuKbls6shE+g5oSfP5/nu0/TrR+dLjGIsXr6f7N+tW+0rDGHtXqOp9Zln4Z4TsEEwUT31uiQgNvnNcRPMVib32+3A9mKdATsD1zZHukPSdrVlavt7xZGcuXWRQpmKFJWomTOhrirn4w9bnmxCrX/aLvUJ1uXmDkobIXjw5+9/PORJGeF8QUqHohlZ6EYWaHNKM1+va7ZpBZV3c63ID+E0Qh0oQCAzGwQ3J086t6AVkysus1Yep4ZAekrLaEIGCErnOqKBBRpDMRkLzmgFFQ+IJAvrjMs1hQzI4jRxCcHSAgzNyTBRuZimiotTbXRcrqdUV2Lk49KVldFoJTVEUM2zJa9Nuk9gLiDMamM4I5SOyc8SrSU/FJkwWpINKb7r7KpQFgSHw4M9zBeLxRDT9tD5fNTKhtEvp8cvfj1/MWCZVSaijqYXPOCcVE7W/IhYZy0XpiZehweHT4aPh4/SDOxCLNF2/LnP03A3UTq98P/n5b/9edlWsEg3cVQZ1Kk3J+LetmXoQswft91QS2oH16ZpMhF32uZlJgput+MLcXs7xUDvvFmtePlTTT71bhbyKeVTJ19PF6nPXnMn688YyUb9hTFiLcEXq+Lfnu1OBGdvzrk/TNtHdZlmMOFxwaMzLsRYfBAfhMiESzmR+mxavxUGbV5jzucbvVz3se49PrHS16kDtx+dVwHaZcfL3WbcXIb/dmb9vshTJtArWj7bHG92viiwaV/NaY4wPwr+Ak/Ha4Y=
sidebar_class_name: "post api-method"
info_path: docs/datamarketplace-individual-api/igrant-io-api-documentation
custom_edit_url: null
---

> **Build this with an AI coding agent.** Install the iGrant.io Agent Skills, then ask your agent to build the integration:
>
> ```bash
> npx skills add L3-iGrant/skills
> ```


import ApiTabs from "@theme/ApiTabs";
import DiscriminatorTabs from "@theme/DiscriminatorTabs";
import MethodEndpoint from "@theme/ApiExplorer/MethodEndpoint";
import SecuritySchemes from "@theme/ApiExplorer/SecuritySchemes";
import MimeTabs from "@theme/MimeTabs";
import ParamsItem from "@theme/ParamsItem";
import ResponseSamples from "@theme/ResponseSamples";
import SchemaItem from "@theme/SchemaItem";
import SchemaTabs from "@theme/SchemaTabs";
import Markdown from "@theme/Markdown";
import OperationTabs from "@theme/OperationTabs";
import TabItem from "@theme/TabItem";

<h1 className={"openapi__heading"}>Token Verification and Authorisation</h1>

<MethodEndpoint method={"post"} path={"/v3/service/data-space/validate-access"}></MethodEndpoint>



The Token Verification and Authorisation endpoint for an organisation in  regards to a Data Marketplace. An Access Token issued as a result of a Pull-Data request can be verified here, and an authorisation decision can be made  against the requested resource (defined by OpenAPI method and path). The  resource is checked against the OpenAPI specification of the underlying  Data Agreement within the Data Disclosure Agreement Record's Template  connected to the Access Token.


## Request

<MimeTabs className={"openapi-tabs__mime"}><TabItem label={"application/json"} value={"application/json-schema"}><details style={{}} className={"openapi-markdown__details mime"} data-collapsed={false} open={true}><summary style={{}} className={"openapi-markdown__details-summary-mime"}><h3 className={"openapi-markdown__details-summary-header-body"}>Body</h3></summary><div style={{"textAlign":"left","marginLeft":"1rem"}}></div><ul style={{"marginLeft":"1rem"}}><SchemaItem collapsible={false} name={"accessToken"} required={true} schemaName={"string"} qualifierMessage={undefined} schema={{"type":"string","description":"The JWT Access Token to be verified and authorised"}}></SchemaItem><SchemaItem collapsible={false} name={"httpMethod"} required={true} schemaName={"string"} qualifierMessage={undefined} schema={{"type":"string","description":"The HTTP Method to be checked against the OpenAPI specification"}}></SchemaItem><SchemaItem collapsible={false} name={"path"} required={true} schemaName={"string"} qualifierMessage={undefined} schema={{"type":"string","description":"The path to be checked against the OpenAPI specification"}}></SchemaItem><SchemaItem collapsible={false} name={"excludeDataClassification"} required={false} schemaName={"bool"} qualifierMessage={undefined} schema={{"type":"bool","description":"Whether to exclude the data classification from the result","default":false}}></SchemaItem><SchemaItem collapsible={false} name={"excludeIndividuals"} required={false} schemaName={"bool"} qualifierMessage={undefined} schema={{"type":"bool","description":"Whether to exclude the individuals from the result","default":false}}></SchemaItem><SchemaItem collapsible={false} name={"excludeDecodedClaims"} required={false} schemaName={"bool"} qualifierMessage={undefined} schema={{"type":"bool","description":"Whether to exclude the decoded claims from the result","default":false}}></SchemaItem></ul></details></TabItem></MimeTabs><div><div><ApiTabs label={undefined} id={undefined}><TabItem label={"200"} value={"200"}><div>

Access token verification result

</div><div><MimeTabs className={"openapi-tabs__mime"} schemaType={"response"}><TabItem label={"application/json"} value={"application/json"}><SchemaTabs className={"openapi-tabs__schema"}><TabItem label={"Schema"} value={"Schema"}><details style={{}} className={"openapi-markdown__details response"} data-collapsed={false} open={true}><summary style={{}} className={"openapi-markdown__details-summary-response"}><strong>Schema</strong></summary><div style={{"textAlign":"left","marginLeft":"1rem"}}></div><ul style={{"marginLeft":"1rem"}}><div><span className={"badge badge--info"}>oneOf</span><SchemaTabs><TabItem label={"MOD1"} value={"0-item-properties"}><SchemaItem collapsible={false} name={"verified"} required={true} schemaName={"boolean"} qualifierMessage={undefined} schema={{"type":"boolean","description":"Whether the access token was verified and authorised","example":true}}></SchemaItem><SchemaItem collapsible={false} name={"dataClassification"} required={true} schemaName={"string"} qualifierMessage={"**Possible values:** [`anonymous`, `pii`]"} schema={{"type":"string","description":"The data classification of the requested resource","enum":["anonymous","pii"]}}></SchemaItem><SchemaItem collapsible={false} name={"individuals"} required={true} schemaName={"object[]"} qualifierMessage={undefined} schema={{"type":"array","items":{"allOf":[{"type":"object","title":"Individual","description":"Shallowly models an Individual which may reference some instance in an external system (registration system, functional ID, foundational ID etc). An Individual instance of this model is not to be mistaken with a unique natural individual. It is up to the system owner to decide if this record permits mapping to a natural individual and/or if a single Individual row can map to several consent agreements.","x-not-in-database":false,"properties":{"id":{"type":"string","format":"","example":"64541a2e6e7569000145cd66","description":"The unique ID of an Individual row."},"externalId":{"type":"string","format":"","example":"user@example.com","description":"Reference to another foundational/functional ID, which is likely PII"},"externalIdType":{"type":"string","format":"","example":"email","description":"External ID type specifier. A string. For instance \"email\" or \"foundational ID\". Can be used in later queries."},"identityProviderId":{"type":"string","format":"","example":"64541a2e6e7569000145ab12","description":"This could be an FK, but for now we do not have a mapping of identity providers. IDBB may have more requirements."}}},{"type":"object","title":"IndividualExtras","required":["name","email","phone"],"properties":{"name":{"type":"string","description":"Name of the individual"},"iamId":{"type":"string","description":"Create a user in keycloak and save the `id` as `iamId`"},"email":{"type":"string","description":"Email ID"},"phone":{"type":"string","description":"Phone"},"pushNotificationToken":{"type":"string","description":"Device token of the individual"},"deviceType":{"type":"string","description":"Device type(OS) of the individual","enum":["android","ios"]},"mapperId":{"type":"string","description":"Defines the mapper id of the individual"}}}],"description":"Data for an individual, returned if the Pull-Data request was made for a specific individual"}}}></SchemaItem><SchemaItem collapsible={true} className={"schemaItem"}><details style={{}} className={"openapi-markdown__details"}><summary style={{}}><span className={"openapi-schema__container"}><strong className={"openapi-schema__property"}>decodedClaims</strong><span className={"openapi-schema__name"}> object</span><span className={"openapi-schema__divider"}></span><span className={"openapi-schema__required"}>required</span></span></summary><div style={{"marginLeft":"1rem"}}><div style={{"marginTop":".5rem","marginBottom":".5rem"}}>

The decoded JWT claims. The fields listed below will be present; additional claims are allowed.

</div><SchemaItem collapsible={false} name={"aud"} required={true} schemaName={"string"} qualifierMessage={undefined} schema={{"type":"string","description":"The audience of the JWT"}}></SchemaItem><SchemaItem collapsible={false} name={"dataClassification"} required={true} schemaName={"string"} qualifierMessage={"**Possible values:** [`anonymous`, `pii`]"} schema={{"type":"string","enum":["anonymous","pii"],"description":"The data classification of the requested resource"}}></SchemaItem><SchemaItem collapsible={false} name={"dataDisclosureAgreementRecordId"} required={true} schemaName={"string"} qualifierMessage={undefined} schema={{"type":"string","description":"The ID of the Data Disclosure Agreement Record associated with this token"}}></SchemaItem><SchemaItem collapsible={false} name={"exp"} required={true} schemaName={"integer"} qualifierMessage={undefined} schema={{"type":"integer","description":"The expiration time of the JWT"}}></SchemaItem><SchemaItem collapsible={false} name={"iat"} required={true} schemaName={"integer"} qualifierMessage={undefined} schema={{"type":"integer","description":"The issued at time of the JWT"}}></SchemaItem><SchemaItem collapsible={false} name={"iss"} required={true} schemaName={"string"} qualifierMessage={undefined} schema={{"type":"string","description":"The issuer of the JWT"}}></SchemaItem><SchemaItem collapsible={false} name={"jti"} required={true} schemaName={"string"} qualifierMessage={undefined} schema={{"type":"string","description":"The unique identifier for the JWT"}}></SchemaItem><SchemaItem name={"property name*"} required={false} schemaName={"any"} qualifierMessage={undefined} schema={{"type":"object","description":"The decoded JWT claims. The fields listed below will be present; additional claims are allowed.","properties":{"aud":{"type":"string","description":"The audience of the JWT"},"dataClassification":{"type":"string","enum":["anonymous","pii"],"description":"The data classification of the requested resource"},"dataDisclosureAgreementRecordId":{"type":"string","description":"The ID of the Data Disclosure Agreement Record associated with this token"},"exp":{"type":"integer","description":"The expiration time of the JWT"},"iat":{"type":"integer","description":"The issued at time of the JWT"},"iss":{"type":"string","description":"The issuer of the JWT"},"jti":{"type":"string","description":"The unique identifier for the JWT"}},"required":["aud","dataClassification","dataDisclosureAgreementRecordId","exp","iat","iss","jti"],"additionalProperties":true}} collapsible={false} discriminator={false}></SchemaItem></div></details></SchemaItem></TabItem><TabItem label={"MOD2"} value={"1-item-properties"}><SchemaItem collapsible={false} name={"verified"} required={true} schemaName={"boolean"} qualifierMessage={undefined} schema={{"type":"boolean","description":"Whether the access token was verified and authorised","example":false}}></SchemaItem><SchemaItem collapsible={false} name={"reason"} required={true} schemaName={"string"} qualifierMessage={undefined} schema={{"type":"string","description":"The reason why the access token verification failed","example":"Invalid signature"}}></SchemaItem></TabItem></SchemaTabs></div></ul></details></TabItem><TabItem label={"Example (from schema)"} value={"Example (from schema)"}><ResponseSamples responseExample={"{}"} language={"json"}></ResponseSamples></TabItem></SchemaTabs></TabItem></MimeTabs></div></TabItem><TabItem label={"401"} value={"401"}><div>

Unauthorized

</div><details style={{"textAlign":"left","marginBottom":"1rem"}} className={"openapi-markdown__details"} data-collaposed={true} open={false}><summary style={{}}><strong>Response Headers</strong></summary><ul style={{"marginLeft":"1rem"}}></ul></details><div><MimeTabs className={"openapi-tabs__mime"} schemaType={"response"}><TabItem label={"application/json"} value={"application/json"}><SchemaTabs className={"openapi-tabs__schema"}><TabItem label={"Schema"} value={"Schema"}><details style={{}} className={"openapi-markdown__details response"} data-collapsed={false} open={true}><summary style={{}} className={"openapi-markdown__details-summary-response"}><strong>Schema</strong></summary><div style={{"textAlign":"left","marginLeft":"1rem"}}></div><ul style={{"marginLeft":"1rem"}}><SchemaItem collapsible={false} name={"errorCode"} required={true} schemaName={"integer"} qualifierMessage={undefined} schema={{"type":"integer","example":400}}></SchemaItem><SchemaItem collapsible={false} name={"errorDescription"} required={true} schemaName={"string"} qualifierMessage={undefined} schema={{"type":"string","example":"Bad input parameter"}}></SchemaItem></ul></details></TabItem><TabItem label={"Example (from schema)"} value={"Example (from schema)"}><ResponseSamples responseExample={"{\n  \"errorCode\": 400,\n  \"errorDescription\": \"Bad input parameter\"\n}"} language={"json"}></ResponseSamples></TabItem></SchemaTabs></TabItem></MimeTabs></div></TabItem><TabItem label={"500"} value={"500"}><div>

Internal server error

</div><details style={{"textAlign":"left","marginBottom":"1rem"}} className={"openapi-markdown__details"} data-collaposed={true} open={false}><summary style={{}}><strong>Response Headers</strong></summary><ul style={{"marginLeft":"1rem"}}></ul></details><div><MimeTabs className={"openapi-tabs__mime"} schemaType={"response"}><TabItem label={"application/json"} value={"application/json"}><SchemaTabs className={"openapi-tabs__schema"}><TabItem label={"Schema"} value={"Schema"}><details style={{}} className={"openapi-markdown__details response"} data-collapsed={false} open={true}><summary style={{}} className={"openapi-markdown__details-summary-response"}><strong>Schema</strong></summary><div style={{"textAlign":"left","marginLeft":"1rem"}}></div><ul style={{"marginLeft":"1rem"}}><SchemaItem collapsible={false} name={"errorCode"} required={true} schemaName={"integer"} qualifierMessage={undefined} schema={{"type":"integer","example":400}}></SchemaItem><SchemaItem collapsible={false} name={"errorDescription"} required={true} schemaName={"string"} qualifierMessage={undefined} schema={{"type":"string","example":"Bad input parameter"}}></SchemaItem></ul></details></TabItem><TabItem label={"Example (from schema)"} value={"Example (from schema)"}><ResponseSamples responseExample={"{\n  \"errorCode\": 400,\n  \"errorDescription\": \"Bad input parameter\"\n}"} language={"json"}></ResponseSamples></TabItem></SchemaTabs></TabItem></MimeTabs></div></TabItem><TabItem label={"headers"} value={"headers"}><div></div><div></div></TabItem></ApiTabs></div></div>
      