Start device authorization
Begins the device authorization grant. Returns a user code and a verification URL that a human opens in a browser to approve the credential, plus a device code to poll with. This is how a CLI or an unattended agent obtains a credential without a password.
POST
/auth/cli/deviceRequest body
requiredapplication/jsonAny of:
object
credentialProtectionstringdefault: "os_keychain"
Allowed:
os_keychainplaintext_localinstallationIdstring<uuid>matches ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
machineCredentialstringhostobjectShow propertiesHide properties
hostnamestringmax length 256
osstringmax length 256
any
anyResponses
201Success.
deviceCodestringrequiredmin length 1
userCodestringrequiredmin length 1
verificationUristring<uri>requiredverificationUriCompletestring<uri>requiredexpiresInSecondsintegerrequiredmax 9007199254740991
pollIntervalSecondsintegerrequiredmax 9007199254740991
400The request failed validation. `field` names the offending input.
statusCodeintegerrequiredHTTP status code, repeated in the body.
min -9007199254740991 · max 9007199254740991
codestringrequiredStable machine-readable error code, e.g. `SECRET_NOT_FOUND` or `FORBIDDEN`. Branch on this, never on the message.
messagestringrequiredHuman-readable explanation. Wording may change.
fieldstringThe offending request field, present on validation failures.
404The resource does not exist, or is not visible to this credential.
statusCodeintegerrequiredHTTP status code, repeated in the body.
min -9007199254740991 · max 9007199254740991
codestringrequiredStable machine-readable error code, e.g. `SECRET_NOT_FOUND` or `FORBIDDEN`. Branch on this, never on the message.
messagestringrequiredHuman-readable explanation. Wording may change.
fieldstringThe offending request field, present on validation failures.
429Rate limited. Retry after the interval named in the response.
statusCodeintegerrequiredHTTP status code, repeated in the body.
min -9007199254740991 · max 9007199254740991
codestringrequiredStable machine-readable error code, e.g. `SECRET_NOT_FOUND` or `FORBIDDEN`. Branch on this, never on the message.
messagestringrequiredHuman-readable explanation. Wording may change.
fieldstringThe offending request field, present on validation failures.
500Unexpected server error. The body never carries internal detail.
statusCodeintegerrequiredHTTP status code, repeated in the body.
min -9007199254740991 · max 9007199254740991
codestringrequiredStable machine-readable error code, e.g. `SECRET_NOT_FOUND` or `FORBIDDEN`. Branch on this, never on the message.
messagestringrequiredHuman-readable explanation. Wording may change.
fieldstringThe offending request field, present on validation failures.
Request
curl -X POST "https://api.varsafe.dev/auth/cli/device" \
-H "Content-Type: application/json" \
-d '{
"credentialProtection": "os_keychain",
"installationId": "<uuid>",
"machineCredential": "grant",
"host": {
"hostname": "string",
"os": "string"
}
}'const response = await fetch("https://api.varsafe.dev/auth/cli/device", {
method: "POST",
headers: {
"Content-Type": "application/json"
},
body: JSON.stringify({
"credentialProtection": "os_keychain",
"installationId": "<uuid>",
"machineCredential": "grant",
"host": {
"hostname": "string",
"os": "string"
}
})
});import requests
response = requests.post(
"https://api.varsafe.dev/auth/cli/device",
headers={
"Content-Type": "application/json"
},
json={
"credentialProtection": "os_keychain",
"installationId": "<uuid>",
"machineCredential": "grant",
"host": {
"hostname": "string",
"os": "string"
}
},
)Response
{
"deviceCode": "string",
"userCode": "string",
"verificationUri": "<uri>",
"verificationUriComplete": "<uri>",
"expiresInSeconds": 0,
"pollIntervalSeconds": 0
}{
"statusCode": 0,
"code": "string",
"message": "string",
"field": "string"
}{
"statusCode": 0,
"code": "string",
"message": "string",
"field": "string"
}{
"statusCode": 0,
"code": "string",
"message": "string",
"field": "string"
}{
"statusCode": 0,
"code": "string",
"message": "string",
"field": "string"
}