View a Token Policy

Endpoint URL: /{customerId}/config/tokenPolicies/{tokenPolicyId}


Returns information for a specific token policy.

Token policies are primarily used to specify token lifetimes. By default, access tokens are valid for 1 hour (3600 seconds) before they expire; you can make the access token lifetime shorter than that value but not longer. Refresh tokens are valid for 90 days (7776000 seconds), but that lifespan can either be shortened, or can be extended to as long as one year.

Token policies are also used to specify the allowed scopes for clients associated with this token policy.

Respects the API Client Allow List: No


This endpoint requires token-based authentication. To obtain an access token, you must use a confidential client (using the client ID as the username and the client secret as the password) to access the /{customerId}/login/token endpoint. The access token returned from the token endpoint is then used in the Authorization header of your API call. For example, if you get back the access token Ki712dpGq5GPQcsxMHY6ShHY7wU_iTs0o9dPx4TEzf5yLIvddjnDVBJxjPDucf5YVB then your Authorization header would look like this when using Curl:

-H 'Authorization: Bearer Ki712dpGq5GPQcsxMHY6ShHY7wU_iTs0o9dPx4TEzf5yLIvddjnDVBJxjPDucf5YVB'

In Postman, set the Authorization Type to Bearer and use the access token as the value of the Token field.

Path Parameters

Path parameters that must be included in the request are listed in the following table:





Unique identifier of the customer associated with the token policy.




Unique identifier of the token policy to be returned.

Sample Request (Curl)

The following command returns the token policy with the policy ID 03ded1ac-ecdb-4bb6-9c40-6b638757e9fb:

curl -X GET \ \
  -H 'Authorization: Bearer c2dueXZ1czZwYzRqbTdraHIybmVxNWdzODlnYnIyZXE6d3Q0YzN1bjl3a2tjZnZ5a25xeDQ0eW5jNDc2YWZzNjg='


200 OK

If your call to this endpoint succeeds, you'll get back detailed information for the specified token policy:

    "id": "03ded1ac-ecdb-4bb6-9c40-6b638757e9fb",
    "accessTokenLifetime": 3000,
    "allowedScopes": [
    "refreshTokenLifetime": 7776000,
    "title": "Phone Only Token Policy",
    "useAccessJWT": false,
    "_links": {
        "self": {
            "href": "/01000000-0000-3000-9000-000000000000/config/tokenPolicies/03ded1ac-ecdb-4bb6-9c40-6b638757e9fb"