---
title: "Start an OAuth device authorization"
method: POST
path: "/api/oauth/device_authorization"
tags: ["OAuth 2.0 / OpenID Connect"]
---

# Start an OAuth device authorization

`POST /api/oauth/device_authorization`

## Response `200`

Device and user codes for browser authorization.

- OAuthDeviceAuthorizationResponse
  - `device_code` string, required
  - `user_code` string, required
  - `verification_uri` string, uri, required
  - `verification_uri_complete` string, uri, required
  - `expires_in` integer, required
  - `interval` integer, required

## Other responses

- `400` — Validation error or precondition failure.
- `401` — Missing or invalid credential.
- `403` — Credential lacks the required scope (Agent Key) or insufficient OAuth scope.
- `404` — Resource does not exist or is invisible to the caller. The two are intentionally indistinguishable.
- `409` — Conflicting state (e.g. legal-entity name already taken).
- `429` — Rate limit exceeded. No `Retry-After` header is currently emitted; back off exponentially.
- `500` — Server error.

---

[API](https://skmtc.dev/eprospera/apis/e-pro-spera-api.md) · [All operations](https://skmtc.dev/eprospera/apis/e-pro-spera-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/eprospera/e-pro-spera-api/revisions/9ecdd3ca5a8c/schema)
