Stack Exchange Access Tokens API

OAuth access token introspection and invalidation.

OpenAPI Specification

stackexchange-access-tokens-api-openapi.yml Raw ↑
openapi: 3.0.3
info:
  title: Stack Exchange Access Tokens API
  description: 'Public, read-mostly HTTP/JSON API spanning all 180+ Stack Exchange sites

    (Stack Overflow, Server Fault, Super User, Ask Ubuntu, Stats, Math Overflow, ...).


    All method families live under a single base URL with a uniform wrapper

    (`items`, `has_more`, `page`, `quota_max`, `quota_remaining`, `backoff`).

    Read access is unauthenticated. Write methods require OAuth 2.0 with the

    appropriate scopes (`write_access`, `private_info`, `no_expiry`).


    Most paths take a required `site` query parameter naming the target Q&A

    community (`stackoverflow`, `serverfault`, `superuser`, ...). Use `/sites`

    to enumerate the network.

    '
  version: '2.3'
  termsOfService: https://stackoverflow.com/legal/api-terms-of-use
  contact:
    name: Stack Exchange API
    url: https://api.stackexchange.com/
  license:
    name: Creative Commons BY-SA 4.0 (content) / API Terms of Use
    url: https://stackoverflow.com/legal/api-terms-of-use
  x-generated-from: documentation
  x-last-validated: '2026-05-29'
servers:
- url: https://api.stackexchange.com/2.3
  description: Stack Exchange API v2.3 production endpoint
security:
- apiKey: []
tags:
- name: Access Tokens
  description: OAuth access token introspection and invalidation.
paths:
  /access-tokens/{accessTokens}/invalidate:
    get:
      tags:
      - Access Tokens
      operationId: invalidateAccessTokens
      summary: Stack Exchange Invalidate Access Tokens
      description: Invalidate the given access tokens. Requires the app's `key`.
      parameters:
      - name: accessTokens
        in: path
        required: true
        description: Up to 100 semicolon-delimited access tokens to invalidate.
        schema:
          type: string
      - $ref: '#/components/parameters/Key'
      - $ref: '#/components/parameters/Filter'
      responses:
        '200':
          description: A page of access tokens with their invalidation status.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AccessTokensResponse'
      x-microcks-operation:
        delay: 0
        dispatcher: FALLBACK
  /access-tokens/{accessTokens}/read:
    get:
      tags:
      - Access Tokens
      operationId: readAccessTokens
      summary: Stack Exchange Read Access Tokens
      description: Inspect the given access tokens (scopes, expiry, account id).
      parameters:
      - name: accessTokens
        in: path
        required: true
        description: Up to 100 semicolon-delimited access tokens to inspect.
        schema:
          type: string
      - $ref: '#/components/parameters/Key'
      - $ref: '#/components/parameters/Filter'
      responses:
        '200':
          description: A page of access tokens.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AccessTokensResponse'
      x-microcks-operation:
        delay: 0
        dispatcher: FALLBACK
  /apps/{accessTokens}/de-authenticate:
    get:
      tags:
      - Access Tokens
      operationId: deauthenticateApp
      summary: Stack Exchange De-Authenticate App
      description: De-authenticate the named app for the holder(s) of the given access tokens.
      parameters:
      - name: accessTokens
        in: path
        required: true
        schema:
          type: string
      - $ref: '#/components/parameters/Key'
      - $ref: '#/components/parameters/Filter'
      responses:
        '200':
          description: A page of access tokens.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AccessTokensResponse'
      x-microcks-operation:
        delay: 0
        dispatcher: FALLBACK
components:
  parameters:
    Key:
      name: key
      in: query
      required: false
      description: App key from stackapps.com. Raises the daily quota to 10,000/IP.
      schema:
        type: string
        example: example_app_key_abcdef
    Filter:
      name: filter
      in: query
      required: false
      description: Custom response filter id created via /filters/create.
      schema:
        type: string
        example: default
  schemas:
    AccessToken:
      type: object
      description: An OAuth access token, returned by the access-token endpoints.
      properties:
        access_token:
          type: string
        expires_on_date:
          type: integer
          format: int64
        account_id:
          type: integer
          format: int64
        scope:
          type: array
          items:
            type: string
    AccessTokensResponse:
      allOf:
      - $ref: '#/components/schemas/Wrapper'
      - type: object
        properties:
          items:
            type: array
            items:
              $ref: '#/components/schemas/AccessToken'
    Wrapper:
      type: object
      description: Common envelope returned by every Stack Exchange API method.
      properties:
        backoff:
          type: integer
          description: Seconds the client MUST wait before re-querying this same method. Returned when the API has identified the consumer as expensive.
          example: 0
        error_id:
          type: integer
          description: Numeric error code when the response is an error.
        error_message:
          type: string
          description: Human-readable error message.
        error_name:
          type: string
          description: Stable error name (e.g. `throttle_violation`).
        has_more:
          type: boolean
          description: True when more pages exist past the returned `page`.
          example: true
        page:
          type: integer
          description: Page number echoed from the request.
          example: 1
        page_size:
          type: integer
          description: Page size echoed from the request.
          example: 30
        quota_max:
          type: integer
          description: Daily quota for the IP/key combination.
          example: 10000
        quota_remaining:
          type: integer
          description: Quota left after this request.
          example: 9999
        total:
          type: integer
          description: Total count when the consumer requested it via filter.
        type:
          type: string
          description: Type name of the items returned.
      required:
      - has_more
      - quota_max
      - quota_remaining
  securitySchemes:
    oauth2:
      type: oauth2
      description: 'OAuth 2.0 explicit or implicit flow. Apps register on stackapps.com.

        Read methods do not require auth; write methods require `write_access`.

        `private_info` is needed for /me/notifications, /me/inbox, and similar

        private surfaces. `no_expiry` issues tokens that never expire.

        '
      flows:
        authorizationCode:
          authorizationUrl: https://stackoverflow.com/oauth
          tokenUrl: https://stackoverflow.com/oauth/access_token
          scopes:
            read_inbox: Access the authenticated user's inbox.
            no_expiry: Issue a token that never expires.
            write_access: Vote, post, comment, flag, accept on the user's behalf.
            private_info: Access endpoints that return personal information.
    apiKey:
      type: apiKey
      in: query
      name: key
      description: 'Optional app key. Sending a key raises the daily quota from 300 to 10,000

        requests per IP and is the recommended default for any non-trivial client.

        '