Skip to content
varsafe
Esc
↑↓navigate↵open⌘Jpreview

Exchange a device code for a CLI credential

Polls the device authorization grant. Every answer is a 201 whose status says where the grant stands: pending (keep polling; reason: slow_down asks for a longer interval), failed (expired or denied — start again), or granted / granted-machine, which carries the credential exactly once.

POST/auth/cli/device/token
Responses
201Success.
One of:
object
statusstringrequired
reasonstringrequired
Allowed:authorization_pendingslow_down
object
statusstringrequired
reasonstringrequired
Allowed:expireddenied
object
statusstringrequired
tokenstringrequired
min length 1
grantIdstring<uuid>required
accountobjectrequired
Show properties
userIdstringrequired
emailstring<email>required
namestring | nullrequired
teamsobject[]required
Show properties
Array of object
teamIdstring<uuid>required
teamNamestringrequired
scopesstring[]required
object
statusstringrequired
tokenstringrequired
min length 1
apiTokenIdstring
min length 1
grantIdstring<uuid>
accountobjectrequired
Show properties
userIdstringrequired
emailstring<email>required
namestring | nullrequired
teamobject
Show properties
teamIdstring<uuid>required
teamNamestringrequired
projectsstring[]
min items 1
environmentsstring[]
min items 1
teamsobject[]
min items 1
Show properties
Array of object
teamIdstring<uuid>required
teamNamestringrequired
scopesstring[]required
expiresAtstring<date-time>required
400The request failed validation. `field` names the offending input.
statusCodeintegerrequired
HTTP status code, repeated in the body.
min -9007199254740991 · max 9007199254740991
codestringrequired
Stable machine-readable error code, e.g. `SECRET_NOT_FOUND` or `FORBIDDEN`. Branch on this, never on the message.
messagestringrequired
Human-readable explanation. Wording may change.
fieldstring
The offending request field, present on validation failures.
401No credential was presented, or it is invalid or revoked.
statusCodeintegerrequired
HTTP status code, repeated in the body.
min -9007199254740991 · max 9007199254740991
codestringrequired
Stable machine-readable error code, e.g. `SECRET_NOT_FOUND` or `FORBIDDEN`. Branch on this, never on the message.
messagestringrequired
Human-readable explanation. Wording may change.
fieldstring
The offending request field, present on validation failures.
403The credential is valid but lacks the required scope, role or team access.
statusCodeintegerrequired
HTTP status code, repeated in the body.
min -9007199254740991 · max 9007199254740991
codestringrequired
Stable machine-readable error code, e.g. `SECRET_NOT_FOUND` or `FORBIDDEN`. Branch on this, never on the message.
messagestringrequired
Human-readable explanation. Wording may change.
fieldstring
The offending request field, present on validation failures.
404The resource does not exist, or is not visible to this credential.
statusCodeintegerrequired
HTTP status code, repeated in the body.
min -9007199254740991 · max 9007199254740991
codestringrequired
Stable machine-readable error code, e.g. `SECRET_NOT_FOUND` or `FORBIDDEN`. Branch on this, never on the message.
messagestringrequired
Human-readable explanation. Wording may change.
fieldstring
The offending request field, present on validation failures.
429Rate limited. Retry after the interval named in the response.
statusCodeintegerrequired
HTTP status code, repeated in the body.
min -9007199254740991 · max 9007199254740991
codestringrequired
Stable machine-readable error code, e.g. `SECRET_NOT_FOUND` or `FORBIDDEN`. Branch on this, never on the message.
messagestringrequired
Human-readable explanation. Wording may change.
fieldstring
The offending request field, present on validation failures.
500Unexpected server error. The body never carries internal detail.
statusCodeintegerrequired
HTTP status code, repeated in the body.
min -9007199254740991 · max 9007199254740991
codestringrequired
Stable machine-readable error code, e.g. `SECRET_NOT_FOUND` or `FORBIDDEN`. Branch on this, never on the message.
messagestringrequired
Human-readable explanation. Wording may change.
fieldstring
The offending request field, present on validation failures.
Request
curl -X POST "https://api.varsafe.dev/auth/cli/device/token"
Response
{
  "status": "pending",
  "reason": "authorization_pending"
}