Validate OAuth session
curl --request GET \
--url https://staging-api.usetyms.com/v1/adam/oauth/token/validate \
--header 'Authorization: <authorization>' \
--header 'X-API-Key: <api-key>'import requests
url = "https://staging-api.usetyms.com/v1/adam/oauth/token/validate"
headers = {
"Authorization": "<authorization>",
"X-API-Key": "<api-key>"
}
response = requests.get(url, headers=headers)
print(response.text)const options = {
method: 'GET',
headers: {Authorization: '<authorization>', 'X-API-Key': '<api-key>'}
};
fetch('https://staging-api.usetyms.com/v1/adam/oauth/token/validate', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));{
"status": "success",
"message": "Business validated successfully",
"data": {
"uuid": "business-uuid",
"name": "Acme LLC",
"email": "owner@example.com",
"logo": null,
"currency": "USD",
"country": "US",
"timezone": "America/New_York",
"authentication_method": "oauth",
"expires_at": "2026-06-16T15:30:00+00:00"
}
}{
"status": "failed",
"message": "App secret required with Bearer"
}{
"status": "failed",
"message": "<string>"
}OAuth
Validate OAuth session
Validate the current OAuth access token and return authorized business profile fields.
GET
/
oauth
/
token
/
validate
Validate OAuth session
curl --request GET \
--url https://staging-api.usetyms.com/v1/adam/oauth/token/validate \
--header 'Authorization: <authorization>' \
--header 'X-API-Key: <api-key>'import requests
url = "https://staging-api.usetyms.com/v1/adam/oauth/token/validate"
headers = {
"Authorization": "<authorization>",
"X-API-Key": "<api-key>"
}
response = requests.get(url, headers=headers)
print(response.text)const options = {
method: 'GET',
headers: {Authorization: '<authorization>', 'X-API-Key': '<api-key>'}
};
fetch('https://staging-api.usetyms.com/v1/adam/oauth/token/validate', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));{
"status": "success",
"message": "Business validated successfully",
"data": {
"uuid": "business-uuid",
"name": "Acme LLC",
"email": "owner@example.com",
"logo": null,
"currency": "USD",
"country": "US",
"timezone": "America/New_York",
"authentication_method": "oauth",
"expires_at": "2026-06-16T15:30:00+00:00"
}
}{
"status": "failed",
"message": "App secret required with Bearer"
}{
"status": "failed",
"message": "<string>"
}Send both
X-API-Key (your app tyms_sk_...) and Authorization: Bearer <access_token>. Same requirement applies to all other business-scoped endpoints when using OAuth.Authorizations
Business secret tyms_sk_... for business-scoped routes. Partner secret for register-business and referred-business distributor routes.
Headers
Bearer OAuth access token from exchange or refresh.
Response
Authorized business profile