A pending `bl login`
const url = 'https://example.com/api/v1/cli/requests/example';const options = { method: 'GET', headers: {cookie: 'bl_authority_session=<bl_authority_session>'}};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request GET \ --url https://example.com/api/v1/cli/requests/example \ --cookie bl_authority_session=<bl_authority_session>Which machine and which version of bl ask for access with this user code, and until when. The approval page shows it before the user logs in at /auth/login?device=<code> to approve, or denies. Only for a person logged in through the identity provider, not for an API key; at most 20 codes a minute.
Authorizations
Section titled “Authorizations”Parameters
Section titled “Parameters”Path Parameters
Section titled “Path Parameters”The user code that bl login shows.
Responses
Section titled “Responses”OK.
object
Example generated
{ "user_code": "example", "device_name": "example", "client_version": "example", "created_at": "2026-04-15T12:00:00Z", "expires_at": "2026-04-15T12:00:00Z"}Not a person logged in through the identity provider.
The body of every failed call to a management API.
object
object
Stable, machine-readable: invalid_request, unauthenticated,
forbidden, not_found, conflict, upstream_unavailable,
unavailable, internal, or a more specific code of the operation.
For people; may change between versions.
Example
{ "error": { "code": "not_found", "message": "unknown negotiation" }}No request with this code; it may have expired.
The body of every failed call to a management API.
object
object
Stable, machine-readable: invalid_request, unauthenticated,
forbidden, not_found, conflict, upstream_unavailable,
unavailable, internal, or a more specific code of the operation.
For people; may change between versions.
Example
{ "error": { "code": "not_found", "message": "unknown negotiation" }}