L31 · OAUTH 2.0
Approve a device from your phone
Start a device authorization request from a terminal, approve it on your phone, and read each answer the token endpoint gives while you poll.
Planned
Steps
Request a device code and user code with curl.
What the server will check: A device authorization request for your client.
Poll the token endpoint before approving.
What the server will check: An authorization_pending answer for that request.
Open the verification page on your phone, sign in as a test user and enter the user code.
What the server will check: The request was approved.
You sign in and decide on the authorization server. The terminal never sees the test user's password.
Poll again.
What the server will check: An access token was issued for the device code.
When it opens
This lab is planned. It opens when these are in place:
- Lab setup and cleanup in your test tenant
- Device authorization at the tenant authorization server
The server checks your test tenant's history for this attempt. You can review the events yourself in your tenant's Audit and Logs.