Developer CLI
Start a CLI sign-in
/oauth/deviceThe first step of RFC 8628. The CLI sends its client id and, for PKCE, the S256 challenge of a verifier it keeps; the answer is a device code (kept by the CLI), a user code (shown to the person) and where to enter it. The code lasts ten minutes. Form-encoded or JSON.
| Field | Description |
|---|---|
client_id | immiscible-cli |
scope | optional; any of agents:read agents:write approvals:read status:read (the default is all four) |
code_challenge, code_challenge_method | optional PKCE: the base64url SHA-256 of a verifier, and S256. With a challenge, only a poll carrying the matching code_verifier gets the token. |
client_name | shown on the approval page, such as “Immiscible CLI on build-7” |
Then poll POST /oauth/token every interval seconds with grant_type=urn:ietf:params:oauth:grant-type:device_code, device_code, client_id and code_verifier. Until the person decides, the answer is 400 with error: authorization_pending; polling faster than the interval answers slow_down and adds five seconds to it; a denial is access_denied; a code past its ten minutes is expired_token. The success answer is { access_token, token_type: "Bearer", expires_in, scope, token_id, workspace, user }, once.
#Authentication
Public
No credential. Public routes are rate limited per address.
The first step of the developer CLI's sign-in (RFC 8628 device authorization). Rate limited per address.