---
title: "Api Auth Device Token"
method: POST
path: "/api/auth/token"
tags: ["Infrastructure"]
---

# Api Auth Device Token

`POST /api/auth/token`

Poll for device authorization result (RFC 8628 §3.4).

Returns:
- 200 + access_token when authorized
- 428 "authorization_pending" while waiting
- 410 "expired_token" if timed out

## Request body

- DeviceTokenRequest
  - `device_code` string, required
  - `grant_type` string

## Response `200`

Successful Response

- unknown

## Other responses

- `422` — Validation Error

## Changes

- **2026-04-05** `f2668775365c` — 1 info
  - endpoint added
- **2026-04-03** `aca6ce6b2785` — 1 breaking
  - api path removed without deprecation

[Change history](https://skmtc.dev/aabiro/apis/xcelsior/changes/api/auth/token/post.md)

---

[API](https://skmtc.dev/aabiro/apis/xcelsior.md) · [All operations](https://skmtc.dev/aabiro/apis/xcelsior/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/aabiro/xcelsior/revisions/f2668775365c/schema)
