The `bl login` to confirm
const url = 'https://example.com/api/v1/cli/consent';const options = {method: 'GET'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request GET \ --url https://example.com/api/v1/cli/consentAfter /auth/login?device=<code> the browser has a cookie (HttpOnly, SameSite=Strict, only for this path, 5 minutes) for the login it made at the identity provider. This shows what that login would approve: the user code, the machine and version of bl, when it asked, and as whom with which roles.
Authorizations
Section titled “Authorizations”- None
Responses
Section titled “Responses”OK.
object
The code to compare with the one in the terminal.
As whom bl will work: the person who just logged in at the IdP.
The roles bl gets.
Example generated
{ "user_code": "example", "device_name": "example", "client_version": "example", "created_at": "2026-04-15T12:00:00Z", "expires_at": "2026-04-15T12:00:00Z", "name": "example", "email": "example", "roles": [ "example" ]}No login waits for confirmation in this browser; it may have expired.
The body of every failed call to a management API.
object
object
Stable, machine-readable: invalid_request, unauthenticated,
forbidden, not_found, conflict, upstream_unavailable,
unavailable, internal, or a more specific code of the operation.
For people; may change between versions.
Example
{ "error": { "code": "not_found", "message": "unknown negotiation" }}