> ## Documentation Index
> Fetch the complete documentation index at: https://usegately.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Verify Token

> Verify a member session token from your backend

Check that a session token sent to your backend was issued by Gately to a member of your project. Gately checks the token's signature and expiry, and that it belongs to the project that owns the API key.

Use this from your server only. In Node.js, [`verifyToken`](/docs/sdk/nodejs) calls this endpoint and caches the result for you.

<Warning>
  Requires a **secret** API key (`gately_sk_...`) in the `Authorization` header. Public keys and project IDs are rejected with `401`.
</Warning>

## Request Body

<ParamField body="token" type="string" required>
  The member's session token (`access_token`)
</ParamField>

## Response

<ResponseField name="valid" type="boolean">
  `true` when the token is valid for your project
</ResponseField>

<ResponseField name="claims" type="object">
  Token claims, present when `valid` is `true`

  <Expandable title="properties">
    <ResponseField name="sub" type="string">Member ID</ResponseField>
    <ResponseField name="email" type="string">Member email</ResponseField>
    <ResponseField name="project_id" type="string">Project the member belongs to</ResponseField>
    <ResponseField name="role" type="string">Member role</ResponseField>
    <ResponseField name="type" type="string">Always `project_member`</ResponseField>
    <ResponseField name="iat" type="number">Issued at (unix seconds)</ResponseField>
    <ResponseField name="exp" type="number">Expires at (unix seconds)</ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="error" type="string">
  Why verification failed, present when `valid` is `false`: `Token expired`, `Invalid token`, `Token was not issued for this project`, or an API key error
</ResponseField>

<RequestExample>
  ```bash cURL theme={null}
  curl -X POST "https://api.usegately.com/api/v1/auth/verify" \
    -H "Authorization: Bearer gately_sk_live_YOUR_SECRET_KEY" \
    -H "Content-Type: application/json" \
    -d '{ "token": "MEMBER_ACCESS_TOKEN" }'
  ```
</RequestExample>

<ResponseExample>
  ```json 200 theme={null}
  {
    "valid": true,
    "claims": {
      "sub": "6f1c2a9e-1b2d-4c7a-9a51-2f0f1e3d4c5b",
      "email": "user@example.com",
      "project_id": "a3b9c1d2-5e6f-4a7b-8c9d-0e1f2a3b4c5d",
      "role": "member",
      "type": "project_member",
      "iat": 1767139200,
      "exp": 1767744000
    }
  }
  ```

  ```json 401 theme={null}
  {
    "valid": false,
    "error": "Token was not issued for this project"
  }
  ```
</ResponseExample>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.