Skip to main content
POST
Check that a session token sent to your backend was issued by Gately to a member of your project. Gately checks the token’s signature and expiry, and that it belongs to the project that owns the API key. Use this from your server only. In Node.js, verifyToken calls this endpoint and caches the result for you.
Requires a secret API key (gately_sk_...) in the Authorization header. Public keys and project IDs are rejected with 401.

Request Body

string
required
The member’s session token (access_token)

Response

boolean
true when the token is valid for your project
object
Token claims, present when valid is true
string
Why verification failed, present when valid is false: Token expired, Invalid token, Token was not issued for this project, or an API key error