oauth

Handles `GET /device_verification` — render data for the browser consent page.

Changed on

Session-authed. Looks up the still-pending, unexpired grant for the given user_code (normalizing the input first) and returns the client name and requested scopes so the page can ask the user to approve. A code that is unknown, expired, or no longer pending yields 404 Not Found so the page can show a distinguishable "invalid or expired code" message.

get/api/v0/main-frontend/oauth/device_verification

Request

  • The document declares no server URL.
  • Auth: none declared

Query parameters

user_codestring required

The user_code shown to the user by the device

Response

Pending device authorization render data

client_idstring required

Public client identifier (the client_id string, not the internal UUID).

client_namestring required

Human-readable client name for display.

scopesstring[] required

Scopes the client is requesting.

user_codestring required

The normalized user_code (XXXX-XXXX), echoed back for display.

Changes