---
id: get-post-oidc-user-info
title: "UserInfo Endpoint"
description: "OpenID Connect UserInfo endpoint that returns claims about the authenticated end-user. Requires a valid access token obtained from the token endpoint to be provided in the `Authorization` header. The endpoint accepts GET and POST. Error answers of the provider have an empty body, and the `WWW-Authenticate` header holds the reason."
sidebar_label: "UserInfo Endpoint"
hide_title: true
hide_table_of_contents: true
api: eJztWM1yGzcSfpUuXGJXjUj5JxdWnIrWUlJMsrFqpZQPkkpsAk0OrBlgDGBIcVm87ZPso+2TbDUwMxz+yHa2dst7iC7izADon6+7v26shSIvna6CtkaMxLuKzPgc3lpjSAb43ZMbm5kFMqqy2gQIOQZwFGpnPMgCdekBp7bmLwRYh5xM0BIDKd50UntyA/gbfay1Iw8ICyy0ApSSvIdgH8iAnQbUhhTMnC3jOen9VqiFKUHl7EIrUqBNXDQ5q0Nunf47svITyAkVC7vOabuVBVXBw08X14BGweW7q+sBXDhnHaDxS3Ie7Cye15zvIMcFARqgsgormFq1yuLeKPT9+/cnZz0zW7mQ20L5uMYRemsGt0ZkokKHJQVyXoxu1nveZk3H56186+ZotI/WiExoXlFhyEUmDJYkRqK/YqxEJlzyqxKj4GrKhJc5lShGaxFWFe/wwWkzF5vNHS/2lTWePH9/eXrK/3b1YbhBm5l1ZauFtCaQCbwWq6pgk7U1ww+eN6wPBdrpB5KBDXe2Ihd0Eufr6aFW2b54oz/WBFqxb2eaHMysi67hKMrAkbfFghQsdcjj+7Q0rKDEIHNt5oAhOD2tA3lo9kosiinKh9bNstBsUCboEcuqYH0+oKGBsvRD82ogbSk2bAN5MiH54oiNqJTmb1hc7lj7ZesYss2+D65jIEaxpEA6ihZi4TmutQftOTLTyRkYG/gRncPVAC5Q5vBAK14UvWMUPbLZCH1LADkPEwYZ+IAuJM/B5Fac3opJc9ICi5p6Yd1ke3Qjhp0jU37o4KGJF1BUkVEebMrVrSGQoitlRwfBWsRwXMggRqJ2ZkS10qNKq9ELXlaiLp7EKf1lIuUhA8BPr1OAf3H8blPpRhCXh7dWEcvm3+c9jO6yz8T6dvc2FLQJNCfXN/n16enmyPFHsmQbqH9Brn5VHaCrK6KxfjeMeCFbRD6kgtgVt7boxRzaKXJfUOOWORnA9uStEmClrJ2H0jri6DBgjaQkOQmEHD1MOtdMorDJvvWTJGG/GnJAc6jPbG3UQPShFvu6Hq1Kx1xJ6MhxrS7KN7f7xHfZuOtWZBCVfHMrtIncdd9Y332677n+za247Co+lLUPzFx1LGy3QhxN90YTmWNRkJnTAMahSbvkoL6z+sJ63urgnetFpNmGg8Qm5cKLI8XeYMOfpBqk+qSsPZTa+1gj2PeJt60Deqw4T9KWGDfapyga7PDF5ivDFM14CqQr8p4Di6OyMehrwvPqEJ4frZtqpcgcwUZZSgkROxUW4KWtCCa2IqPV5P8YG1/PZloyA99HnZ8CaJxQhG/iqm8S+cTOL8H69bB6/YdoZZ8qgg7Rd613kvEHrVC/QW0bl8a/7c7BceL5fJsV++N4vrSKsthkNaDCZK/ITTKYGBvuY+WdcPpPPLkFufvkTtFS2L36NIcdqpDc2rV4Sfno415X0JgkOh3EUXnit5YdxBEy7D6mvLhE75fWqYIT6lc71wboMZDpCoKhBTmYUhxBcFrwZNJo2WelXSJisd/+wZ7DGno3i3PB/zJMNtm6O+/sctx6+u6oo/voPuHrsQnkDBaQ1m6RO3D80ZX/cVegA0g0XPYccX/aT9Z9LDaZ8CRrp8Mq+jcVBi5yYnRzx7Zz4rSD1EjMKVxaH96Nz9+2My+jgHMe28SeS+HZX5ErERk04Tk3hCWF3PI5lfWxIeSxbSSGi1dDNl1LGnYhNrRayeF6d5bbDHnE0Uls8taxgfGcSts4U2SidtwU5yFUfjQcKirtCVZ6oOcOTRhoG5HfPeDSWVXL2FM9ccznTrgKOOdx4YntPn3eV+Rui8cVh38qWGeV/oVWvXKB6UUz/CZAt+Pvzrx/kAsc2jz89O4gOEljtKVRpkmQ4/cGXbNWOZrpx3bKnCQdYQLPjA2JbINDXUQfVCjpeQY0mA/2jh1Bs/G7la0du+PkgVbfTzgdd6JxLabx6cc4FomR+Pn99aFtffav0PtWvYbwks5MjztKQOfBWHPYh0mY6GYYxk1wusTYa4oXyli82rHL11VlXfhhi2cHif5p+2o3EPoxtGdNtwme/esf/3weZ1q4WpLSPgeFAYEeZY5mTrEeLMjpWQMnNOm0TXxm+NqTB0/F7MTbBTnSc9NdDWTNfq7j/Xk6AwSl5zpgAUtuF0IU5i13HZVVEEjmxhZ2rslniQjimAyGllDQggoOKB7sIgnjVBd8E8GHYB0s36CYOUhbVoVGIykBFs1zNK+LaI9nzBBmdVFw5Codop4lGpOKWqElGR9LdJsFFcqc4OXg9MDny+VygPHzwLr5sNnrh7+O3178dnVxwns2W3LZ4sC5o6ysy+62IxNcghJeL09fvh68GryIVyLWhxJNT5/ujvCiuXPbj94eIf55v/jfvl9s0jjQYxhWBWrDIMWoWDcsdCMWrxpS0TLeaLRMJDLBXCQyMTq4Wezo6C4TOZPa6Eas11P09LsrNht+/bEmx+x6l4kFuphgibK0j02TGM2w8PSJaHjW4KaewyevQo8a2VKGYb6IBV6MhMjEAzPK/lXp5q4beaKOadFZBK+3/aBd2/TJnbHl27ymbjcKdBW1+dFr53Z1+64p1tccfN93msZYZAU3m38De/1UZA==
sidebar_class_name: "post api-method"
info_path: docs/extensions-api/igrant-io-api-documentation
custom_edit_url: null
---

> **Build this with an AI coding agent.** Install the iGrant.io Agent Skills, then ask your agent to build the integration:
>
> ```bash
> npx skills add L3-iGrant/skills
> ```


import ApiTabs from "@theme/ApiTabs";
import DiscriminatorTabs from "@theme/DiscriminatorTabs";
import MethodEndpoint from "@theme/ApiExplorer/MethodEndpoint";
import SecuritySchemes from "@theme/ApiExplorer/SecuritySchemes";
import MimeTabs from "@theme/MimeTabs";
import ParamsItem from "@theme/ParamsItem";
import ResponseSamples from "@theme/ResponseSamples";
import SchemaItem from "@theme/SchemaItem";
import SchemaTabs from "@theme/SchemaTabs";
import Markdown from "@theme/Markdown";
import OperationTabs from "@theme/OperationTabs";
import TabItem from "@theme/TabItem";

<h1 className={"openapi__heading"}>UserInfo Endpoint</h1>

<MethodEndpoint method={"post"} path={"/v3/service/extension/oidc/{organisationId}/userinfo"}></MethodEndpoint>



OpenID Connect UserInfo endpoint that returns claims about the authenticated end-user. Requires a valid access token obtained from the token endpoint to be provided in the `Authorization` header. The endpoint accepts GET and POST. Error answers of the provider have an empty body, and the `WWW-Authenticate` header holds the reason.


## Request

<details style={{"marginBottom":"1rem"}} className={"openapi-markdown__details"} data-collapsed={false} open={true}><summary style={{}}><h3 className={"openapi-markdown__details-summary-header-params"}>Path Parameters</h3></summary><div><ul><ParamsItem className={"paramsItem"} param={{"description":"The ID of the organisation","in":"path","name":"organisationId","required":true,"schema":{"type":"string"}}}></ParamsItem></ul></div></details><div><div><ApiTabs label={undefined} id={undefined}><TabItem label={"200"} value={"200"}><div>

User information

</div><details style={{"textAlign":"left","marginBottom":"1rem"}} className={"openapi-markdown__details"} data-collaposed={true} open={false}><summary style={{}}><strong>Response Headers</strong></summary><ul style={{"marginLeft":"1rem"}}></ul></details><div><MimeTabs className={"openapi-tabs__mime"} schemaType={"response"}><TabItem label={"application/json"} value={"application/json"}><SchemaTabs className={"openapi-tabs__schema"}><TabItem label={"Schema"} value={"Schema"}><details style={{}} className={"openapi-markdown__details response"} data-collapsed={false} open={true}><summary style={{}} className={"openapi-markdown__details-summary-response"}><strong>Schema</strong></summary><div style={{"textAlign":"left","marginLeft":"1rem"}}></div><ul style={{"marginLeft":"1rem"}}><SchemaItem collapsible={false} name={"sub"} required={false} schemaName={"string"} qualifierMessage={undefined} schema={{"type":"string","description":"Unique identifier for the user, resolved with the identity matching attributes or the callback of the client","example":"jane.doe@example.com"}}></SchemaItem><SchemaItem collapsible={true} className={"schemaItem"}><details style={{}} className={"openapi-markdown__details"}><summary style={{}}><span className={"openapi-schema__container"}><strong className={"openapi-schema__property"}>presentation</strong><span className={"openapi-schema__name"}> object</span></span></summary><div style={{"marginLeft":"1rem"}}><div style={{"marginTop":".5rem","marginBottom":".5rem"}}>

The presented credentials. This is an object, not an array. Each key is the index of a presentation as a string, starting at `"0"`. Each value holds the claims of that presentation, and its content depends on the credential format.


</div><SchemaItem collapsible={true} className={"schemaItem"}><details style={{}} className={"openapi-markdown__details"}><summary style={{}}><span className={"openapi-schema__container"}><strong className={"openapi-schema__property"}>property name*</strong><span className={"openapi-schema__name"}> object</span></span></summary><div style={{"marginLeft":"1rem"}}><SchemaItem name={"property name*"} required={false} schemaName={"any"} qualifierMessage={undefined} schema={{"type":"object","additionalProperties":true}} collapsible={false} discriminator={false}></SchemaItem></div></details></SchemaItem></div></details></SchemaItem></ul></details></TabItem><TabItem label={"Example (from schema)"} value={"Example (from schema)"}><ResponseSamples responseExample={"{\n  \"sub\": \"jane.doe@example.com\",\n  \"presentation\": {\n    \"0\": {\n      \"vct\": \"urn:eudi:pid:1\",\n      \"email\": \"jane.doe@example.com\"\n    }\n  }\n}"} language={"json"}></ResponseSamples></TabItem></SchemaTabs></TabItem></MimeTabs></div></TabItem><TabItem label={"400"} value={"400"}><div>

Bad request. The provider answers with an empty body and the `WWW-Authenticate` header when a request parameter occurs more than once. The answer has `errorCode` and `errorDescription` when the organisation is not found.

</div><details style={{"textAlign":"left","marginBottom":"1rem"}} className={"openapi-markdown__details"} data-collaposed={true} open={false}><summary style={{}}><strong>Response Headers</strong></summary><ul style={{"marginLeft":"1rem"}}><li className={"schemaItem"}><summary style={{}}><strong>WWW-Authenticate</strong><span style={{"opacity":"0.6"}}> string</span></summary><div><div style={{"marginTop":".5rem","marginBottom":".5rem"}}>

The Bearer challenge. It holds `error` and `error_description` when the provider gives a reason.

</div></div></li></ul></details><div><MimeTabs className={"openapi-tabs__mime"} schemaType={"response"}><TabItem label={"application/json"} value={"application/json"}><SchemaTabs className={"openapi-tabs__schema"}><TabItem label={"Schema"} value={"Schema"}><details style={{}} className={"openapi-markdown__details response"} data-collapsed={false} open={true}><summary style={{}} className={"openapi-markdown__details-summary-response"}><strong>Schema</strong></summary><div style={{"textAlign":"left","marginLeft":"1rem"}}></div><ul style={{"marginLeft":"1rem"}}><SchemaItem collapsible={false} name={"errorCode"} required={true} schemaName={"integer"} qualifierMessage={undefined} schema={{"type":"integer","example":400}}></SchemaItem><SchemaItem collapsible={false} name={"errorDescription"} required={true} schemaName={"string"} qualifierMessage={undefined} schema={{"type":"string","example":"Bad input parameter"}}></SchemaItem></ul></details></TabItem><TabItem label={"Example (from schema)"} value={"Example (from schema)"}><ResponseSamples responseExample={"{\n  \"errorCode\": 400,\n  \"errorDescription\": \"Bad input parameter\"\n}"} language={"json"}></ResponseSamples></TabItem></SchemaTabs></TabItem></MimeTabs></div></TabItem><TabItem label={"401"} value={"401"}><div>

Unauthorized. The access token is missing, not valid or expired. The body is empty.

</div><details style={{"textAlign":"left","marginBottom":"1rem"}} className={"openapi-markdown__details"} data-collaposed={true} open={false}><summary style={{}}><strong>Response Headers</strong></summary><ul style={{"marginLeft":"1rem"}}><li className={"schemaItem"}><summary style={{}}><strong>WWW-Authenticate</strong><span style={{"opacity":"0.6"}}> string</span></summary><div><div style={{"marginTop":".5rem","marginBottom":".5rem"}}>

The Bearer challenge. It holds `error` and `error_description` when the provider gives a reason.

</div></div></li></ul></details><div></div></TabItem><TabItem label={"403"} value={"403"}><div>

Forbidden. The access token does not have the scope `openid`. The body is empty.

</div><details style={{"textAlign":"left","marginBottom":"1rem"}} className={"openapi-markdown__details"} data-collaposed={true} open={false}><summary style={{}}><strong>Response Headers</strong></summary><ul style={{"marginLeft":"1rem"}}><li className={"schemaItem"}><summary style={{}}><strong>WWW-Authenticate</strong><span style={{"opacity":"0.6"}}> string</span></summary><div><div style={{"marginTop":".5rem","marginBottom":".5rem"}}>

The Bearer challenge. It holds `error` and `error_description` when the provider gives a reason.

</div></div></li></ul></details><div></div></TabItem><TabItem label={"404"} value={"404"}><div>

Not found. The Passwordless Login extension has never been enabled for the organisation.

</div><details style={{"textAlign":"left","marginBottom":"1rem"}} className={"openapi-markdown__details"} data-collaposed={true} open={false}><summary style={{}}><strong>Response Headers</strong></summary><ul style={{"marginLeft":"1rem"}}></ul></details><div><MimeTabs className={"openapi-tabs__mime"} schemaType={"response"}><TabItem label={"application/json"} value={"application/json"}><SchemaTabs className={"openapi-tabs__schema"}><TabItem label={"Schema"} value={"Schema"}><details style={{}} className={"openapi-markdown__details response"} data-collapsed={false} open={true}><summary style={{}} className={"openapi-markdown__details-summary-response"}><strong>Schema</strong></summary><div style={{"textAlign":"left","marginLeft":"1rem"}}></div><ul style={{"marginLeft":"1rem"}}><SchemaItem collapsible={false} name={"error"} required={false} schemaName={"string"} qualifierMessage={undefined} schema={{"type":"string","description":"The error code, for example `invalid_request`, `not_found` or `server_error`"}}></SchemaItem><SchemaItem collapsible={false} name={"error_description"} required={false} schemaName={"string"} qualifierMessage={undefined} schema={{"type":"string","description":"The reason for the error"}}></SchemaItem></ul></details></TabItem><TabItem label={"Example (from schema)"} value={"Example (from schema)"}><ResponseSamples responseExample={"{\n  \"error\": \"string\",\n  \"error_description\": \"string\"\n}"} language={"json"}></ResponseSamples></TabItem><TabItem label={"Example"} value={"Example"}><ResponseSamples responseExample={"{\n  \"error\": \"not_found\",\n  \"error_description\": \"Not found\"\n}"} language={"json"}></ResponseSamples></TabItem></SchemaTabs></TabItem></MimeTabs></div></TabItem><TabItem label={"500"} value={"500"}><div>

Internal server error. The answer has `errorCode` and `errorDescription` when it cannot reach the provider.

</div><details style={{"textAlign":"left","marginBottom":"1rem"}} className={"openapi-markdown__details"} data-collaposed={true} open={false}><summary style={{}}><strong>Response Headers</strong></summary><ul style={{"marginLeft":"1rem"}}></ul></details><div><MimeTabs className={"openapi-tabs__mime"} schemaType={"response"}><TabItem label={"application/json"} value={"application/json"}><SchemaTabs className={"openapi-tabs__schema"}><TabItem label={"Schema"} value={"Schema"}><details style={{}} className={"openapi-markdown__details response"} data-collapsed={false} open={true}><summary style={{}} className={"openapi-markdown__details-summary-response"}><strong>Schema</strong></summary><div style={{"textAlign":"left","marginLeft":"1rem"}}></div><ul style={{"marginLeft":"1rem"}}><div><span className={"badge badge--info"}>oneOf</span><SchemaTabs><TabItem label={"Provider error"} value={"0-item-properties"}><SchemaItem collapsible={false} name={"error"} required={false} schemaName={"string"} qualifierMessage={undefined} schema={{"type":"string","description":"The error code, for example `invalid_request`, `not_found` or `server_error`"}}></SchemaItem><SchemaItem collapsible={false} name={"error_description"} required={false} schemaName={"string"} qualifierMessage={undefined} schema={{"type":"string","description":"The reason for the error"}}></SchemaItem></TabItem><TabItem label={"API error"} value={"1-item-properties"}><SchemaItem collapsible={false} name={"errorCode"} required={true} schemaName={"integer"} qualifierMessage={undefined} schema={{"type":"integer","example":400}}></SchemaItem><SchemaItem collapsible={false} name={"errorDescription"} required={true} schemaName={"string"} qualifierMessage={undefined} schema={{"type":"string","example":"Bad input parameter"}}></SchemaItem></TabItem></SchemaTabs></div></ul></details></TabItem><TabItem label={"Example (from schema)"} value={"Example (from schema)"}><ResponseSamples responseExample={"{\n  \"error\": \"server_error\",\n  \"error_description\": \"Internal server error\"\n}"} language={"json"}></ResponseSamples></TabItem></SchemaTabs></TabItem></MimeTabs></div></TabItem></ApiTabs></div></div>
      