> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://docs.getunleash.io/api/validate-token/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.getunleash.io/_mcp/server. # Validates a token GET https://app.unleash-instance.example.com/auth/reset/validate If the token is valid returns the user that owns the token Reference: https://docs.getunleash.io/api/validate-token ## Authentication - `Authorization` header (required) — API key needed to access this API - `Authorization` header (bearer token, required) — API key needed to access this API, in Bearer token format ## Response ### 200 tokenUserSchema - `id` (integer, required) — The user id - `email` (string, required) — The email of the user - `token` (string, required) — A token uniquely identifying a user - `createdBy` (string, required, nullable) — A username or email identifying which user created this token - `role` (roleSchema, required) — A role holds permissions to allow Unleash to decide what actions a role holder is allowed to perform - `name` (string, optional) — The name of the user ## Errors ### 401 Unauthorized Error Authorization information is missing or invalid. Provide a valid API token as the `authorization` header, e.g. `authorization:*.*.my-admin-token`. - `id` (string, optional) — The ID of the error instance - `name` (string, optional) — The name of the error kind - `message` (string, optional) — A description of what went wrong. ### 415 Unsupported Media Type Error The operation does not support request payloads of the provided type. Please ensure that you're using one of the listed payload types and that you have specified the right content type in the "content-type" header. - `id` (string, optional) — The ID of the error instance - `name` (string, optional) — The name of the error kind - `message` (string, optional) — A description of what went wrong. ## Types ### roleSchema A role holds permissions to allow Unleash to decide what actions a role holder is allowed to perform - `id` (integer, required) — The role id - `type` (string, required) — A role can either be a global root role (applies to all projects) or a project role - `name` (string, required) — The name of the role - `description` (string, optional) — A more detailed description of the role and what use it's intended for - `project` (string, optional, nullable) — What project the role belongs to ## Examples **Response** ```json { "id": 7, "email": "test@example.com", "token": "user:xyzrandomstring", "createdBy": "admin@example.com", "role": { "id": 9, "type": "root", "name": "Editor", "description": "Users with the editor role have access to most features in Unleash but can not manage users and roles in the global scope. Editors will be added as project owners when creating projects and get superuser rights within the context of these projects. Users with the editor role will also get access to most permissions on the default project by default.", "project": "default" }, "name": "Test McTest" } ``` **SDK Code** ```python import requests url = "https://app.unleash-instance.example.com/auth/reset/validate" headers = {"Authorization": ""} response = requests.get(url, headers=headers) print(response.json()) ``` ```javascript const url = 'https://app.unleash-instance.example.com/auth/reset/validate'; const options = {method: 'GET', headers: {Authorization: ''}}; try { const response = await fetch(url, options); const data = await response.json(); console.log(data); } catch (error) { console.error(error); } ``` ```go package main import ( "fmt" "net/http" "io" ) func main() { url := "https://app.unleash-instance.example.com/auth/reset/validate" req, _ := http.NewRequest("GET", url, nil) req.Header.Add("Authorization", "") res, _ := http.DefaultClient.Do(req) defer res.Body.Close() body, _ := io.ReadAll(res.Body) fmt.Println(res) fmt.Println(string(body)) } ``` ```ruby require 'uri' require 'net/http' url = URI("https://app.unleash-instance.example.com/auth/reset/validate") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true request = Net::HTTP::Get.new(url) request["Authorization"] = '' response = http.request(request) puts response.read_body ``` ```java import com.mashape.unirest.http.HttpResponse; import com.mashape.unirest.http.Unirest; HttpResponse response = Unirest.get("https://app.unleash-instance.example.com/auth/reset/validate") .header("Authorization", "") .asString(); ``` ```php request('GET', 'https://app.unleash-instance.example.com/auth/reset/validate', [ 'headers' => [ 'Authorization' => '', ], ]); echo $response->getBody(); ``` ```csharp using RestSharp; var client = new RestClient("https://app.unleash-instance.example.com/auth/reset/validate"); var request = new RestRequest(Method.GET); request.AddHeader("Authorization", ""); IRestResponse response = client.Execute(request); ``` ```swift import Foundation let headers = ["Authorization": ""] let request = NSMutableURLRequest(url: NSURL(string: "https://app.unleash-instance.example.com/auth/reset/validate")! as URL, cachePolicy: .useProtocolCachePolicy, timeoutInterval: 10.0) request.httpMethod = "GET" request.allHTTPHeaderFields = headers let session = URLSession.shared let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in if (error != nil) { print(error as Any) } else { let httpResponse = response as? HTTPURLResponse print(httpResponse) } }) dataTask.resume() ```