---
title: "Poll for a CLI device token"
method: POST
path: "/v1/auth/device/token"
tags: ["Auth"]
---

# Poll for a CLI device token

`POST /v1/auth/device/token`

Redeems an approved device code once. A 409 authorization_pending response is expected until a person approves the code.

## Request body

- DeviceAuthorizationTokenRequest
  - `deviceCode` string, required
  - `clientId` string, required
  - `codeVerifier` string, required

## Response `200`

One-time CLI access token.

- object
  - `success` true, required
  - `data` DeviceAuthorizationToken, required
    - `accessToken` string, required
    - `tokenType` 'Bearer', required

## Other responses

- `400` — The request payload or parameters are invalid.
- `401` — Authentication is missing, invalid, or expired.
- `402` — The requested operation requires a paid plan. API access (organization API keys) requires the Starter plan or higher; a downgraded organization receives this error until its plan is restored.
- `403` — The authenticated principal cannot access the resource.
- `404` — The requested resource was not found.
- `409` — The request conflicts with the current resource state.
- `413` — The request body exceeds the 1 MB limit.
- `429` — The rate limit was exceeded. API key limits are set by plan tier (Starter 600/min, Pro 1500/min, Enterprise 3000/min). Check the Retry-After header before retrying.
- `500` — An unexpected internal error occurred.

---

[API](https://skmtc.dev/inth/apis/inth-api.md) · [All operations](https://skmtc.dev/inth/apis/inth-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/inth/inth-api/revisions/97262bd49ddd/schema)
