Device Code Grant
The device code grant (urn:ietf:params:oauth:grant-type:device_code, RFC 8628) lets a device that can't show a login page get tokens for a user. Smart TVs, CLIs, and IoT devices are the usual cases. The device shows a short code, the user signs in on their phone or computer, and the device polls Descope until the user finishes.
Set up as an authentication method
Device code isn't a toggle under an Inbound App's Grant Types. You turn it on under Settings > Authentication Methods > Device Authentication, and devices use it with the client ID of a Federated OIDC App. For the full setup, see Device Authentication.
How It Works
- The device posts its
client_idand scopes to the Device Authorization endpoint,/oauth2/v1/device. Descope returns adevice_code, auser_code, averification_uri(andverification_uri_complete), how long the codes last, and the pollinginterval. - The device shows the user code and the verification URL, or a QR code that encodes
verification_uri_complete. - On their phone or computer, the user opens the URL. A verification Flow checks the user code, signs the user in, and asks them to approve the device.
- The device polls
/oauth2/v1/tokenwithgrant_type=urn:ietf:params:oauth:grant-type:device_codeand thedevice_code, waiting at least theintervalbetween calls. Until the user finishes, Descope answersauthorization_pending, orslow_downif the device polls too fast. - After the user approves, Descope returns an access token, an ID token, and a refresh token. If the user denies or the codes expire, polling ends with
access_deniedorexpired_token.
Select any step to see what happens. The device shows a code, the user enters it somewhere else, and the device polls until they finish.
Device Code or CIBA
Both grants let a user approve a request on a different device from the one asking for tokens. They differ in how the user finds out about the request:
- Device code: The device shows a code, and the user goes to a URL to enter it. Use it when the device has a screen the user is looking at, such as a TV or a terminal.
- CIBA: Descope contacts the user directly, for example with an email link, and the client polls until they answer. Use it when there's no screen to show a code on, or the request comes from a backend or an agent. CIBA is an Inbound App grant.
Configure in the Console
Under Device Authentication settings, you can set:
- Enable method in API and SDK: Device code only runs through the API and SDKs, so this toggle turns it on or off entirely.
- User code format and characters: The pattern and character set of the code the device shows.
- Expiration time: How long the user code and device code stay valid. The default is 3 minutes.
- Device hosting URL: Where the verification Flow is hosted, such as Auth Hosting or your own page.
Related
- Device Authentication: request and response examples, and how to build the verification Flow
- Grant Types overview
- CIBA