OAuth2 & OpenID Connect Deep Dive · Lekcja

Grant autoryzacji urządzenia

Poznaj OAuth2 Device Authorization Grant (RFC 8628), używany przez urządzenia o ograniczonych możliwościach wprowadzania danych, takie jak telewizory smart, konsole i narzędzia CLI, do uzyskiwania tokenów za pośrednictwem drugiego urządzenia.

Lekcja 4 z 413 kroki

Grant autoryzacji urządzenia to bezpłatna lekcja OAuth2 & OpenID Connect Deep Dive na CoddyKit. To lekcja 4 z 4. Możesz przeczytać całą lekcję poniżej za darmo — a potem ćwiczyć ją interaktywnie w przeglądarce z wbudowanym edytorem kodu i tutorem AI dostępnym 24/7. To część ścieżki edukacyjnej OAuth2 & OpenID Connect Deep Dive, a Twój postęp synchronizuje się między webem a aplikacją CoddyKit. Kurs OAuth2 & OpenID Connect Deep Dive zawiera 4 lekcji w sumie.

Części tej lekcji nie zostały jeszcze przetłumaczone i są wyświetlane po angielsku.

Why a Device Grant?

Some clients have no browser or only a limited keypad: smart TVs, media consoles, printers, and CLI tools. The classic Authorization Code Flow assumes a rich browser for the user-agent redirect, which these devices cannot provide.

The Device Authorization Grant (RFC 8628) solves this by letting the user complete authorization on a second device (phone or laptop) while the constrained device polls for the result.

The Two Endpoints

The flow introduces a new device authorization endpoint alongside the standard token endpoint.

  • /device_authorization — the device requests codes here.
  • /token — the device polls here with grant type urn:ietf:params:oauth:grant-type:device_code.

No redirect URI is involved at all.

Step 1: Requesting Device Codes

The device makes a POST to the device authorization endpoint with its client_id and desired scope.

POST /device_authorization HTTP/1.1
Host: auth.example.com
Content-Type: application/x-www-form-urlencoded

client_id=tv-app-123&scope=profile email

Step 2: The Response

The server returns a device_code (used by the machine), a user_code (typed by the human), a verification_uri, an expires_in, and an interval for polling.

{
  "device_code": "GmRhmhcxhwAzkoEqiMEg",
  "user_code": "WDJB-MJHT",
  "verification_uri": "https://example.com/device",
  "expires_in": 900,
  "interval": 5
}

Step 3: User Instructions

The device displays a short message: Go to example.com/device and enter code WDJB-MJHT.

A verification_uri_complete may also be returned, embedding the code so a QR code can carry the whole link.

Step 4: User Authorizes

On their phone or laptop, the user opens the verification URI, logs in, enters the user_code, and approves the requested scopes. This happens in a full browser, so MFA and rich consent screens all work normally.

Step 5: Device Polls the Token Endpoint

Meanwhile the device polls the token endpoint at the given interval, sending the device_code.

POST /token HTTP/1.1
Host: auth.example.com
Content-Type: application/x-www-form-urlencoded

grant_type=urn:ietf:params:oauth:grant-type:device_code
&device_code=GmRhmhcxhwAzkoEqiMEg
&client_id=tv-app-123

Polling Responses

Until the user finishes, the server returns errors that tell the device how to behave:

  • authorization_pending — keep polling, user has not approved yet.
  • slow_down — increase the interval by 5 seconds.
  • access_denied — user rejected; stop.
  • expired_token — codes expired; restart.

Step 6: Success

Once the user approves, the next poll returns a normal token response with an access_token (and optionally a refresh_token), exactly like other grants.

{
  "access_token": "eyJhbGciOi...",
  "token_type": "Bearer",
  "expires_in": 3600,
  "refresh_token": "8xLOxBtZp8"
}

A Simple Poll Loop

A pseudo-implementation of the polling logic, respecting slow_down:

let interval = 5;
while (true) {
  await sleep(interval * 1000);
  const res = await pollToken(deviceCode);
  if (res.access_token) return res;
  if (res.error === 'slow_down') interval += 5;
  else if (res.error === 'authorization_pending') continue;
  else throw new Error(res.error);
}

Security Considerations

Keep user_codes short but high-entropy to resist brute force, and rate-limit the verification page. Because there is no redirect, phishing risk shifts to the verification URI — always show the user exactly which app and scopes they are approving.

Quick Check

Test your understanding of the device grant.

Recap

The Device Authorization Grant lets browserless devices authenticate users via a second device.

  • Device gets a device_code + user_code from the device endpoint.
  • User approves on a phone/laptop at the verification URI.
  • Device polls the token endpoint, handling authorization_pending and slow_down.
  • On approval it receives normal access and refresh tokens.
Bezpłatny start

Ucz się OAuth2 & OpenID Connect Deep Dive dzięki korepetycjom AI — za darmo

Pisz i uruchamiaj kod w przeglądarce, otrzymuj natychmiastową pomoc od korepetytora AI dostępnego 24/7 i kontynuuj naukę w sieci lub w aplikacji.

Kursy
12
Lekcje
48

Często zadawane pytania

Czy lekcja „Grant autoryzacji urządzenia” jest bezpłatna?

Tak — pełny tekst „Grant autoryzacji urządzenia” jest dostępny za darmo tutaj w sieci. Aby ćwiczyć ją interaktywnie (wbudowany edytor kodu i tutor AI dostępny 24/7) i odblokować resztę kursu OAuth2 & OpenID Connect Deep Dive, przejdź na CoddyKit PRO. Kurs OAuth2 & OpenID Connect Deep Dive zawiera 4 lekcji w sumie.

Co nauczysz się w „Grant autoryzacji urządzenia”?

Poznaj OAuth2 Device Authorization Grant (RFC 8628), używany przez urządzenia o ograniczonych możliwościach wprowadzania danych, takie jak telewizory smart, konsole i narzędzia CLI, do uzyskiwania to… Ćwiczysz OAuth2 & OpenID Connect Deep Dive z praktycznym kodem, który uruchamiasz bezpośrednio w przeglądarce, a tutor AI dostępny 24/7 odpowiada na Twoje pytania podczas pracy nad lekcją.

Czy potrzebuję doświadczenia, aby zacząć OAuth2 & OpenID Connect Deep Dive?

Nie wymagamy żadnego doświadczenia. OAuth2 & OpenID Connect Deep Dive w CoddyKit jest strukturyzowany dla początkujących i zaawansowanych użytkowników, więc możesz zacząć tutaj lub od początku i uczyć się w swoim tempie. To lekcja 4 z 4.

Ile czasu zajmuje lekcja „Grant autoryzacji urządzenia”?

Większość lekcji CoddyKit trwa około 5–10 minut. Każda lekcja to mały, interaktywny krok, dzięki czemu robisz systematyczne postępy i zawsze wracasz dokładnie do tego samego miejsca — na webie i w aplikacji.

Czy mogę pisać i uruchamiać kod w tej lekcji OAuth2 & OpenID Connect Deep Dive?

Tak. Każda lekcja OAuth2 & OpenID Connect Deep Dive zawiera wbudowany edytor kodu, więc piszesz i uruchamiasz prawdziwy kod bezpośrednio w przeglądarce i od razu otrzymujesz sprzężenie zwrotne od AI — bez konfiguracji na komputerze.

Wszystkie lekcje w tym kursie

  1. Przepływ Authorization Code
  2. Przepływ Client Credentials
  3. Przepływ Implicit i jego wycofanie
  4. Grant autoryzacji urządzenia
← Powrót do OAuth2 & OpenID Connect Deep Dive