Skip to content

Device authorization

Request

Initiate the device flow (See OAuth 2.0 Device Authorization Grant (RFC 8628)). This call returns a user code and verification URI for the user to approve or deny access on a separate device. Additionally, a device code is provided to obtain the token.

Bodyapplication/x-www-form-urlencodedrequired
client_idstringrequired

Client ID for which authentication is requested.

client_secretstringrequired

Client secret.

scopestringrequired

Scope of the requested access. Used to request specific user details like email. Must include openid and can include additional values (space delimited). offline_access scope allows refreshing access tokens.

Enum:"openid""email""phone""offline_access"
acr_valuesstringrequired

Requested ACR values, specified as a space-separated string. The acr claim of the resulting ID token will indicate which requirements were satisfied.

Enum ValueDescription
urn:transmit:google_direct

Requires Google authentication method to be used for this process.

urn:transmit:apple_direct

Requires Apple authentication method to be used for this process.

urn:transmit:facebook_direct

Requires Facebook authentication method to be used for this process.

urn:transmit:line_direct

Requires Line authentication method to be used for this process.

urn:transmit:centralized

Requires centralized authentication method to be used for this process, centralized is used to request authentication via the Authentication Hub.

loginTypestringdeprecated

Authentication method to be used for this process, where centralized is used to request authentication via the Authentication Hub.

Enum:"google-direct""apple-direct""facebook-direct""webauthn-direct""line-direct""centralized"
curl -i -X POST \
  https://api.sbx.transmitsecurity.io/cis/oidc/device/auth \
  -H 'Content-Type: application/x-www-form-urlencoded' \
  -d client_id=string \
  -d client_secret=string \
  -d scope=openid \
  -d loginType=google-direct \
  -d acr_values=urn:transmit:google_direct

Responses

The authorization request has been accepted

Bodyapplication/json
device_codestringrequired

The device code to be used to obtain a token.

user_codestringrequired

The user code to be displayed to the user.

verification_uristring

The URI that verifies the user submitted a valid user code on the input page.

verification_uri_completestring

(Recommended) The URI with embedded user code that verifies if the user code is valid while skipping the input page.

expires_inintegerrequired

The number of seconds before the device_code expires.

Default:600
Response
{ "device_code": "string", "user_code": "string", "verification_uri": "string", "verification_uri_complete": "string", "expires_in": 600 }