Validate an ALLOW auth token

API key required. Checks an `authToken` from an ALLOW response: signature, expiry (90 seconds from mint), and — when `verb`, `target`, or `purpose` are supplied — that the token is bound to exactly that write. Anything else is purpose drift and returns `valid: false`. **Important:** an invalid token is HTTP 200 with `{"valid": false, "reason": "..."}` — only a bad API key is a 401. Call this at commit time, after the agent performs the write, to prove the write matches what Writ allowed.

Authentication

AuthorizationBearer
Your Writ API key (writ_...) as an Authorization Bearer header. The sponsor token (writ_sp_...) is a separate credential used only for grants, revokes, and reinstate — it goes in the same Authorization header on those endpoints. In the Fern docs playground, paste the key here; it is stored in this browser only.

Request

This endpoint expects an object.
tokenstringRequired

The writ_at_… auth token from an ALLOW response.

verbstringOptional
If given, the token must be bound to exactly this verb.
targetstringOptional
If given, the token must be bound to exactly this target.
purposestringOptional
If given, the token must be bound to exactly this purpose.

Response

{valid: true, claims} or {valid: false, reason}. Possible reasons: not a Writ auth token, malformed token, bad signature, malformed payload, token expired, or token not bound to this verb/target/purpose.

Errors

400
Bad Request Error
401
Unauthorized Error