The Token Introspection Endpoint (RFC 7662) allows clients or other entities receiving OAuth 2.0 tokens to determine the validity of an Access Token or Refresh Token. This is necessary in scenarios where the client forwards any token to another party on behalf of the user. Using this feature, that party can verify the validity and some attributes of the provided token.
The RFC does not distinguish between Access Tokens and Refresh Tokens in the context of this endpoint; receiving a successful response therefore doesn't imply the token being an Access Token. It is the callers responsibility to know the type of the token.