Skip to content

Developer CLI

Start a CLI sign-in

POST/oauth/device

The first step of RFC 8628. The CLI sends its client id and, for PKCE, the S256 challenge of a verifier it keeps; the answer is a device code (kept by the CLI), a user code (shown to the person) and where to enter it. The code lasts ten minutes. Form-encoded or JSON.

FieldDescription
client_idimmiscible-cli
scopeoptional; any of agents:read agents:write approvals:read status:read (the default is all four)
code_challenge, code_challenge_methodoptional PKCE: the base64url SHA-256 of a verifier, and S256. With a challenge, only a poll carrying the matching code_verifier gets the token.
client_nameshown on the approval page, such as “Immiscible CLI on build-7”

Then poll POST /oauth/token every interval seconds with grant_type=urn:ietf:params:oauth:grant-type:device_code, device_code, client_id and code_verifier. Until the person decides, the answer is 400 with error: authorization_pending; polling faster than the interval answers slow_down and adds five seconds to it; a denial is access_denied; a code past its ten minutes is expired_token. The success answer is { access_token, token_type: "Bearer", expires_in, scope, token_id, workspace, user }, once.

#Authentication

Public

No credential. Public routes are rate limited per address.

The first step of the developer CLI's sign-in (RFC 8628 device authorization). Rate limited per address.