---
title: "Task 3: Test the Workflow"
description: Test the Show Permissions in Token workflow by completing sign-on and verifying application permissions in the access token claims
component: pingone-api
page_id: pingone-api:workflow-library:pingone-authorize/show-permissions-in-token/test-the-workflow/index
canonical_url: https://developer.pingidentity.com/pingone-api/workflow-library/pingone-authorize/show-permissions-in-token/test-the-workflow/index.html
llms_txt: https://developer.pingidentity.com/pingone-api/llms.txt
docs_for_agents: https://developer.pingidentity.com/build-with-ai/docs-for-agents.md
revdate: 2026-08-11
section_ids:
  what-youll-do: What you'll do
---

# Task 3: Test the Workflow

The Test the Workflow endpoints perform the following actions:

* Send an authorization request.

* Perform any sign-on actions.

* Return an access token.

The authorization and token endpoints that you'll call to test the workflow require an application ID and secret to complete the sign-on action. The Postman collections that accompany these flows use the application you created in the Configure Your Environment collection.

## What you'll do

You will complete a sign-on flow and then verify that the application permissions you assigned to the application role exists in the token claims.

* POST request to the authorize endpoint.

* POST request to submit the user's login credentials.

* POST request to get the access token.

* POST request to call the token introspection endpoint.

|   |                                                                                                                                                                                                                                                                                                                                                                                 |
| - | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|   | If you choose to use an alternate application, be aware that the variables in the Postman collections point to the application ID and secret that you created in the Environment Configuration collection. You must change these values manually either in your Postman environment or in the endpoint's URL or parameters to run the request using your alternate application. |

[Run in Postman](https://god.gw.postman.com/run-collection/3468883-db6467d1-073b-4646-b0e5-e0b0d0c97233?action=collection%2Ffork\&source=rip_markdown\&collection-url=entityId%3D3468883-db6467d1-073b-4646-b0e5-e0b0d0c97233%26entityType%3Dcollection%26workspaceId%3D3550b170-7818-4801-b1eb-dcb7b3f64263#?env%5BPingOne%20Workflow%20Library%20Template%20%28release%3A%202025-04-17%29%5D=W3sia2V5IjoidGxkIiwidmFsdWUiOiJjb20iLCJlbmFibGVkIjp0cnVlLCJ0eXBlIjoiZGVmYXVsdCJ9LHsia2V5IjoiYXV0aFBhdGgiLCJ2YWx1ZSI6Imh0dHBzOi8vYXV0aC5waW5nb25lLnt7dGxkfX0iLCJlbmFibGVkIjp0cnVlLCJ0eXBlIjoiZGVmYXVsdCJ9LHsia2V5IjoiYXBpUGF0aCIsInZhbHVlIjoiaHR0cHM6Ly9hcGkucGluZ29uZS57e3RsZH19L3YxIiwiZW5hYmxlZCI6dHJ1ZSwidHlwZSI6ImRlZmF1bHQifSx7ImtleSI6ImFkbWluRW52SUQiLCJ2YWx1ZSI6IiIsImVuYWJsZWQiOnRydWUsInR5cGUiOiJkZWZhdWx0In0seyJrZXkiOiJhZG1pbkFwcElEIiwidmFsdWUiOiIiLCJlbmFibGVkIjp0cnVlLCJ0eXBlIjoiZGVmYXVsdCJ9LHsia2V5IjoiYWRtaW5BcHBTZWNyZXQiLCJ2YWx1ZSI6IiIsImVuYWJsZWQiOnRydWUsInR5cGUiOiJkZWZhdWx0In0seyJrZXkiOiJlbnZJRCIsInZhbHVlIjoiIiwiZW5hYmxlZCI6dHJ1ZSwidHlwZSI6ImRlZmF1bHQifV0=)
