Ga naar inhoud

The `bl login` to confirm

GET
/api/v1/cli/consent
curl --request GET \
--url https://example.com/api/v1/cli/consent

After /auth/login?device=<code> the browser has a cookie (HttpOnly, SameSite=Strict, only for this path, 5 minutes) for the login it made at the identity provider. This shows what that login would approve: the user code, the machine and version of bl, when it asked, and as whom with which roles.

  • None

OK.

Media typeapplication/json
object
user_code
required

The code to compare with the one in the terminal.

string
device_name
required
string
client_version
required
string
created_at
required
string format: date-time
expires_at
required
string format: date-time
name
required

As whom bl will work: the person who just logged in at the IdP.

string
email
string | null
roles
required

The roles bl gets.

Array<string>

Example generated

{
"user_code": "example",
"device_name": "example",
"client_version": "example",
"created_at": "2026-04-15T12:00:00Z",
"expires_at": "2026-04-15T12:00:00Z",
"name": "example",
"email": "example",
"roles": [
"example"
]
}

No login waits for confirmation in this browser; it may have expired.

Media typeapplication/json

The body of every failed call to a management API.

object
error
required
object
code
required

Stable, machine-readable: invalid_request, unauthenticated, forbidden, not_found, conflict, upstream_unavailable, unavailable, internal, or a more specific code of the operation.

string
message
required

For people; may change between versions.

string

Example

{
"error": {
"code": "not_found",
"message": "unknown negotiation"
}
}