OAuth Authentication

Start RFC8628 device authorization

Changed on

Starts OAuth 2.0 Device Authorization Grant (RFC 8628). Returns device_code for the CLI and user_code for browser verification.

By default the returned verification_uri / verification_uri_complete point at the project's managed device-approval page served by this API (/projects/{projectId}/auth/hosted?action=device&user_code=...&anon_key=...), which requires managed auth enabled and a default anon key for the project.

Projects can override this by setting device_verification_url on the auth config (PATCH /auth/config). When set, that URL is returned as-is with the user_code appended (no action=device hint and no embedded anon key — the page brings its own), so a CLI's login command surfaces the project's own RFC 8628 approval page. With a custom URL, device login does not require managed auth to be enabled; the custom page's origin must be in the project's auth CORS allowlist to call POST /auth/device/verify. Either way the verification page must authenticate the end user and call POST /auth/device/verify with the user_code. See the device-auth guide for both approaches.

post/auth/device/authorize

Request

  • Base URL: https://api.volcano.dev
  • URL: https://api.volcano.dev/auth/device/authorize
  • Auth: none declared

Request body

client_idstring required

Enabled device OAuth client ID for the target project

Response

Device authorization started

device_codestring required
user_codestring required
verification_uristring required

Browser verification URL. Points at the project's managed device approval page served by this API: /projects/{projectId}/auth/hosted?action=device&anon_key=.... Requires the project to have managed auth enabled and a default anon key. A custom CLI may ignore this and direct users to its own RFC 8628-compatible page instead (see the device-auth guide).

verification_uri_completestring required

Same as verification_uri but with the user_code prefilled (&user_code=...). This is the URL most device clients open.

expires_ininteger required
intervalinteger required

Changes

    • ▲

      the response's body type changed from no type to object for status

    • ▲

      the response's body type changed from no type to object for status

    • ○

      added the optional property to the response with the status

    • ○

      added the required property to the response with the status

    • ○

      added the required property to the response with the status

    • ○

      added the required property to the response with the status

    • ○

      added the required property to the response with the status

    • ○

      added the required property to the response with the status

    • ○

      added the required property to the response with the status

    • ○

      added the required property to the response with the status

    • ▲

      the response's body type changed from object to no type for status

    • ▲

      the response's body type changed from object to no type for status

    • ▲

      removed the required property from the response with the status

    • ▲

      removed the required property from the response with the status

    • ▲

      removed the required property from the response with the status

    • ▲

      removed the required property from the response with the status

    • ▲

      removed the required property from the response with the status

    • ▲

      removed the required property from the response with the status

    • ▲

      removed the required property from the response with the status

    • ●

      removed the optional property from the response with the status