OAuth Authentication

Approve or deny a device code

Changed on

Browser-side endpoint for authenticated auth-users to approve (approve) or deny (deny) a user_code.

Called by the verification page after the end user signs in. The grant is scoped to the project the auth-user token belongs to: approving a user_code issued for a different project returns 403. This endpoint does not require managed auth to be enabled, so a custom verification page (hosted anywhere) can drive approval — it just needs an authenticated project auth-user access token and, for cross-origin browser calls, the page origin allowed in the project's auth CORS settings.

post/auth/device/verify

Request

  • Base URL: https://api.volcano.dev
  • URL: https://api.volcano.dev/auth/device/verify
  • Auth: HTTP bearer

Request body

user_codestring required
action'approve' | 'deny'

Response

Verification action accepted

successboolean
statusstring

Changes

    • ▲

      the response's body type changed from no type to object for status

    • ○

      added the optional property to the response with the status

    • ○

      added the required property to the response with the status

    • ▲

      the response's body type changed from object to no type for status

    • ▲

      removed the required property from the response with the status

    • ●

      removed the optional property from the response with the status