Start `bl login` (device authorization)
const url = 'https://example.com/api/v1/cli/device';const options = { method: 'POST', headers: {DPoP: 'example', 'Content-Type': 'application/x-www-form-urlencoded'}, body: new URLSearchParams({client_id: 'example', device_name: 'example', client_version: 'example'})};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://example.com/api/v1/cli/device \ --header 'Content-Type: application/x-www-form-urlencoded' \ --header 'DPoP: example' \ --data client_id=example \ --data device_name=example \ --data client_version=exampleRFC 8628 §3.1 with client_id=bl, and a DPoP proof (RFC 9449) that binds the device code to the key of bl: only that key gets the tokens. A user approves at verification_uri_complete: after a login at the identity provider, on an explicit confirmation page. At most 30 device codes per minute for the service. Only a service that offers bl login (the connector, not the authority).
Authorizations
Section titled “Authorizations”- None
Parameters
Section titled “Parameters”Header Parameters
Section titled “Header Parameters”A DPoP proof for this request.
Request Bodyrequired
Section titled “Request Bodyrequired”object
Always bl.
The name of the machine, shown to the user who approves.
The version of bl, shown to the user who approves.
Example generated
client_id=example&device_name=example&client_version=exampleResponses
Section titled “Responses”OK.
RFC 8628 §3.2.
object
Eight consonants, for the user to compare.
Seconds.
Seconds between polls of the token endpoint.
Example generated
{ "device_code": "example", "user_code": "example", "verification_uri": "example", "verification_uri_complete": "example", "expires_in": 1, "interval": 1}invalid_request, invalid_dpop_proof.
An OAuth 2.0 error (RFC 6749 §5.2).
object
Example
{ "error": "invalid_request"}invalid_client: the client is not bl.
An OAuth 2.0 error (RFC 6749 §5.2).
object
Example
{ "error": "invalid_request"}slow_down: too many login requests.
An OAuth 2.0 error (RFC 6749 §5.2).
object
Example
{ "error": "invalid_request"}