> ## Documentation Index
> Fetch the complete documentation index at: https://docs.turrisfi.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Test OAuth

> Verify that an OAuth JWT token is valid and working

Use this endpoint to verify that your OAuth JWT token is properly configured and working.

The v2 response also carries **`orgCategory`**, telling you which kind of organization the credential you just sent belongs to: `upstreamEntity` for a carrier, MGA or wholesaler, `downstreamEntity` for an agency. It is a four-value enum: `enterpriseUpstreamEntity` and `enterpriseDownstreamEntity` also exist, for surfaces that are not routable yet. Match the value you expect rather than treating anything that is not `upstreamEntity` as an agency. [Which API is mine?](/which-api-is-mine#how-to-tell-which-credential-you-hold) has the full mapping.

That is the fastest way to resolve the most common integration confusion. If a request returns 403 with `invalid_organization_category`, call this endpoint with the same token: it will tell you which surface that credential is actually for. A carrier credential reaches `/v2/upstream/*`; an agency credential reaches `/v2/downstream/*`. See [Authentication](/authentication) for the full surface rules.

<Note>
  This is a test endpoint intended for debugging authentication issues. It returns no business data beyond the category of your own organization.
</Note>


## OpenAPI

````yaml openapi/v2.json GET /v2/auth/test-oauth
openapi: 3.0.0
info:
  title: Turris Public API
  description: API for managing insurance compliance data
  version: 2.0.0
  contact: {}
servers:
  - url: https://public.api.live.turrisfi.com
    description: Production
  - url: https://public.api.sandbox.turrisfi.com
    description: Sandbox
security: []
tags: []
paths:
  /v2/auth/test-oauth:
    get:
      tags:
        - auth
      operationId: AuthController_testOauthV2_v2
      parameters: []
      responses:
        '200':
          description: OAuth token is valid
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    $ref: '#/components/schemas/TestOauthV2Response'
                  requestId:
                    type: string
                    description: Unique request identifier
                    example: dev-2c5e7cf2-9acf-4c8c-ab2f-b81f39d775a8
                  timestamp:
                    type: string
                    description: Response timestamp
                    example: '2025-11-12T20:49:03.293Z'
                required:
                  - data
                  - requestId
                  - timestamp
        '401':
          description: Invalid or missing OAuth token
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponseDto'
components:
  schemas:
    TestOauthV2Response:
      type: object
      properties:
        message:
          type: string
          description: Confirmation message indicating the token is valid
        orgCategory:
          type: string
          description: The kind of organization this credential belongs to
          enum:
            - upstreamEntity
            - downstreamEntity
          example: downstreamEntity
      required:
        - message
        - orgCategory
    ErrorResponseDto:
      type: object
      properties:
        statusCode:
          type: number
          description: HTTP status code
        requestId:
          type: string
          description: Unique request identifier for debugging
        errorType:
          type: string
          description: >-
            Machine-readable error classification. Branch on this rather than on
            `errorMessage`, which is prose and may change. Authentication
            failures returned by our identity provider are forwarded verbatim,
            so a 401 can carry a code outside this list; treat an unrecognised
            value as a generic failure of its HTTP status.
          enum:
            - conflict
            - contact_not_authorized
            - document_exceeds_page_limit
            - downstream_entity_member_exists
            - duplicate_external_id_error
            - duplicate_member_email
            - duplicate_producer_code_error
            - forbidden
            - gateway_timeout
            - inactive_email
            - internal_server_error
            - invalid_email
            - invalid_email_for_invites
            - invalid_organization_category
            - invalid_organization_slug
            - invalid_phone_number
            - invalid_token
            - invite_limit_reached
            - jwt_invalid
            - m2m_client_not_found
            - not_found
            - organization_already_exists
            - organization_slug_already_used
            - payment_required
            - producer_agreement_required
            - product_feature_subscription_required
            - service_unavailable
            - session_authorization_error
            - some_custom_error_string
            - throttled
            - too_many_requests
            - unauthorized
            - unauthorized_client
            - unexpected_400_stytch_error
            - unexpected_403_stytch_error
            - unexpected_404_stytch_error
            - unexpected_error
            - unexpected_stytch_error
            - unprocessable_entity
            - validation_error
          example: validation_error
        errorMessage:
          description: Array of error messages
          type: array
          items:
            type: string
        timestamp:
          type: string
          description: ISO timestamp when the error occurred
        details:
          type: object
          description: Additional error context
      required:
        - statusCode
        - requestId
        - errorType
        - errorMessage
        - timestamp

````

## Related topics

- [Which API Is Mine?](/which-api-is-mine.md)
- [Authentication](/authentication.md)
- [Get OAuth Token](/api-reference/v2/authentication/get-oauth-token.md)
