Get current authorization
Returns the current token scopes and its exact grant policy without accepting a grant identifier.
Authorizations
Per-request RFC 9449 DPoP proof signed with ES256. Protected requests use Authorization: DPoP your_access_token_here. Create a new proof for the exact method and normalized target URI, and include the server nonce when challenged.
OAuth 2.0 with RFC 9700 security practices. Discover exact environment endpoints from /.well-known/openid-configuration and /.well-known/oauth-authorization-server, and discover the resource from /.well-known/oauth-protected-resource. Authorization-code clients use PKCE S256, the exact environment resource, nonce with openid, and DPoP binding. Confidential clients also require PAR and private_key_jwt. Access and refresh tokens are sender-constrained with DPoP. purchases:execute is unavailable and omitted from this scope registry.
Headers
Optional caller request identifier. Unsafe values are replaced with a generated UUID.
^[A-Za-z0-9._~-]{8,128}$Response
The current effective authorization.
Effective authorization for the current access token and grant.
Scopes granted to the current access token and OAuth grant.
1 - 32 elementsA released OAuth scope supported by the authorization server.
accounts:read, activity:read, authorization:read, beneficiaries:read, beneficiaries:write, cards:manage, cards:read, identity:read, kyc:read, offline_access, openid, operations:read, purchases:read, services:read, spending:read, spending:withdraw, transfers:quote Current delegated purchase policy, or null when the grant has no policy.