Skip to main content

Device Authorization

The Device Authorization Grant is a type of flow used to authenticate headless devices, or devices that have limited input options. It is often used within CLIs or TV set-top devices where either browsers, or keyboard input, is limited or unavailable.

Implementation​

This flow is implemented as a two-part process.

  1. The start function is used to initiate sign in from the server, which returns a device code, user code, and a verification URI. These values are returned to the developer in the form of a Context object.
  2. Once the context object is received, the developer passes that context to the resume function, which causes the flow to begin polling the server, waiting for a token to be returned.

The developer should present the user code and verification URI to the user, prompting them to open the verification URI on a different device where they can enter the user code. The user signs in on that separate device, and subsequently grants access to their account from the initiating device. Once this occurs, the polling process initiated in the resume function should complete.