Device Authorization
RFC 8628 device-authorization grant for CLI and other browserless clients
- Request a device + user code (RFC 8628 §3.2)
- Exchange a device_code or refresh token for a CLI token pair
- Revoke a CLI refresh token family
- List the caller's active CLI sessions
- Revoke a single CLI session owned by the caller
- Revoke every active CLI session belonging to the caller
- User-facing verification page
- Normalize a submitted user_code and redirect to the consent panel
- Approve a pending device authorization
- Deny a pending device authorization
- List CLI sessions for org members (admin)
- Revoke a member's CLI session (admin)