OAuth 2.0 endpoints for the Iron Brick sandbox. Exchange application credentials for a short-lived bearer token and validate tokens. Live on dev.ironbrick.us. Agency deployments use the agency identity provider (for example Login.gov, Okta, or Entra ID with PIV/CAC) with the same token semantics.
Base URLs
https://dev.ironbrick.usIron Brick sandbox (live)
Authentication
Authenticate with your application client ID and secret using HTTP Basic. See Authentication.
POST /oauth/token
Get an access token
Client credentials grant (RFC 6749 section 4.4). Authenticate with HTTP Basic (preferred) or form fields. Tokens are JWTs valid for 3600 seconds. Request a subset of your application's scopes with scope.
Request body application/x-www-form-urlencoded
grant_type=client_credentials&scope=cases:readResponses
| 200 | Token issued |
| 400 | invalid_request, unsupported_grant_type, or invalid_scope |
| 401 | invalid_client |
| 429 | slow_down |
curl -X POST "https://dev.ironbrick.us/oauth/token" \
-u "$CLIENT_ID:$CLIENT_SECRET" \
-d grant_type=client_credentials \
-d scope=cases:read{
"access_token": "eyJhbGciOiJIUzI1NiIsInR5cCI6ImF0K2p3dCJ9.eyJpc3MiOi...",
"token_type": "Bearer",
"expires_in": 3600,
"scope": "cases:read"
}POST /oauth/introspect
Validate a token
Token introspection (RFC 7662). Authenticate with any application on the same account. Returns active: false for tokens that are expired, revoked, rotated, malformed, or owned by another account.
Request body application/x-www-form-urlencoded
token=eyJhbGciOiJIUzI1NiIs...Responses
| 200 | Introspection result |
| 401 | invalid_client |
curl -X POST "https://dev.ironbrick.us/oauth/introspect" \
-u "$CLIENT_ID:$CLIENT_SECRET" \
-d token="$TOKEN"{
"active": true,
"scope": "cases:read",
"client_id": "ib_4f0c2a9d8e1b7c3a5f6d2e10",
"token_type": "Bearer",
"exp": 1791043200,
"iat": 1791039600,
"nbf": 1791039600,
"sub": "ib_4f0c2a9d8e1b7c3a5f6d2e10",
"aud": "ironbrick-sandbox",
"iss": "https://dev.ironbrick.us",
"jti": "9b1e6f0a4c2d8e7f1a3b5c6d",
"plan": "sandbox"
}