Resource Guides
Endpoints
Token Management
Customer Management
Account Management
Bre-B Key Management
Recipient Management
Payment Management
QR codes
Title
Message
Create new category
What is the title of your new category?
Edit page index title
What is the title of the page index?
Edit category
What is the new title of your category?
Edit link
What is the new title and URL of your link?
List Token Information
Summarize Page
Copy Markdown
Open in ChatGPT
Open in Claude
Overview
This endpoint retrieves a paginated list of all OAuth tokens issued for the entity. It includes metadata such as roles, scopes, expiration times, and creation dates. This is useful for auditing, monitoring active sessions, and managing token lifecycle.
Endpoint Details
| Definition | Description |
|---|---|
| Endpoint | https://api.paas.sandbox.co.passportfintech.com/v1/iam/oauth/tokens |
| Method | GET |
| Headers | Accept-Language, Content-Length, Content-Type: application/json, Authorization |
| Authentication | Access Token (Bearer Token) |
Request Body
This endpoint does not require a request body.
Example Request
JSON
2
2
1
curl --location 'https://api.paas.sandbox.co.passportfintech.com/v1/iam/oauth/tokens' \2
--header 'Authorization: Bearer <YOUR_ACCESS_TOKEN>' \Response
- HTTP Status Code 200 OK.
Example of Response
JSON
303
303
1
{2
"pagination_info": {...},7
"tokens": [...]303
}Common Errors and Handling
| HTTP Status Code | Meaning | Description |
|---|---|---|
| 400 | Bad Request | Invalid query parameters or malformed request |
| 401 | Unauthorized | Bearer token missing, expired, or does not include iam.oauth.tokens.list.get scope |
| 403 | Forbidden | Authenticated user lacks permission to view token list |
| 500 | Internal Server Error | Unexpected error. Retry or contact support if issue persists |
Best Practices
- Use the
pagination_infoobject to iterate through all pages when retrieving tokens. - Regularly audit active tokens to ensure compliance with security policies.
- Immediately revoke compromised or unused tokens using the Revoke Token endpoint.
- Never expose raw tokens in logs or client-side applications.
- Use
rolesandscopesto enforce least-privilege access models.
Type to search, ESC to discard
Type to search, ESC to discard
Type to search, ESC to discard
Last updated on
Next to read:
Revoke Access TokenDiscard Changes
Do you want to discard your current changes and overwrite with the template?
Archive Synced Block
Message
Create new Template
What is this template's title?
Delete Template
Message