Initiate the device flow (See OAuth 2.0 Device Authorization Grant (RFC 8628)). This call returns a user code and verification URI for the user to approve or deny access on a separate device. Additionally, a device code is provided to obtain the token.
Scope of the requested access. Used to request specific user details like email. Must include openid and can include additional values (space delimited). offline_access scope allows refreshing access tokens.
Requested ACR values, specified as a space-separated string. The acr claim of the resulting ID token will indicate which requirements were satisfied.
| Enum Value | Description |
|---|---|
| urn:transmit:google_direct | Requires Google authentication method to be used for this process. |
| urn:transmit:apple_direct | Requires Apple authentication method to be used for this process. |
| urn:transmit:facebook_direct | Requires Facebook authentication method to be used for this process. |
| urn:transmit:line_direct | Requires Line authentication method to be used for this process. |
| urn:transmit:centralized | Requires centralized authentication method to be used for this process, |
- Sandbox environmenthttps://api.sbx.transmitsecurity.io/cis/oidc/device/auth
- US production environmenthttps://api.transmitsecurity.io/cis/oidc/device/auth
- EU production environmenthttps://api.eu.transmitsecurity.io/cis/oidc/device/auth
- CA production environmenthttps://api.ca.transmitsecurity.io/cis/oidc/device/auth
- AU production environmenthttps://api.au.transmitsecurity.io/cis/oidc/device/auth
- JP production environmenthttps://api.gasne1-ts01.transmitsecurity.io/cis/oidc/device/auth
curl -i -X POST \
https://api.sbx.transmitsecurity.io/cis/oidc/device/auth \
-H 'Content-Type: application/x-www-form-urlencoded' \
-d client_id=string \
-d client_secret=string \
-d scope=openid \
-d loginType=google-direct \
-d acr_values=urn:transmit:google_directThe authorization request has been accepted
(Recommended) The URI with embedded user code that verifies if the user code is valid while skipping the input page.
{ "device_code": "string", "user_code": "string", "verification_uri": "string", "verification_uri_complete": "string", "expires_in": 600 }