Device Authorization Grant
The Device Authorization Grant enables devices with no browser or limited input โ smart TVs, CLIs, streaming sticks, hardware encoders โ to get access tokens by having the user approve on a secondary device like their phone.
When to use this
Use the Device Authorization Grant when your app runs on a device where opening a browser or typing a URL is impractical. The user is shown a short code and a URL; they visit the URL on their phone or computer, enter the code, and approve access. The device polls until authorization is complete or the code expires.
The flow has no redirect URI. The device POSTs to the device authorization endpoint and receives a device_code, a user_code, and a verification_uri. It displays the user code and URL, then polls the token endpoint with grant_type=urn:ietf:params:oauth:grant-type:device_code at the specified interval. Once the user completes authorization on their secondary device, the next poll returns an access token.
More resources
- Device Flow (oauth.com)
- Add the OAuth 2.0 Device Flow to any OAuth Server (Aaron Parecki)
- Device Code on the OAuth 2.0 Playground (oauth.com)