0Pricing
OAuth2 & OpenID Connect Deep Dive · Ders

Cihaz Yetkilendirme İzni

Akıllı televizyonlar, konsollar ve CLI araçları gibi giriş kapasitesi sınırlı cihazların ikincil bir cihaz üzerinden belirteç almasını sağlayan OAuth2 Cihaz Yetkilendirme İznini (RFC 8628) öğrenin.

Cihaz Yetkilendirme İzni, CoddyKit'te ücretsiz bir OAuth2 & OpenID Connect Deep Dive dersidir. Bu, 4 dersinin 4. dersidir. Aşağıdan dersin tamamını ücretsiz okuyabilir, sonra tarayıcıda yerleşik kod editörü ve 7/24 yapay zeka koçu ile uygulamalı olarak pratik yapabilirsin. Bu, OAuth2 & OpenID Connect Deep Dive öğrenme yolunun bir parçasıdır ve ilerlemeniz web ve CoddyKit uygulaması arasında senkronize olur. OAuth2 & OpenID Connect Deep Dive kursu toplamda 4 dersten oluşur.

Bu dersin bazı bölümleri henüz çevrilmemiş olup İngilizce olarak gösterilmektedir.

Why a Device Grant?

Some clients have no browser or only a limited keypad: smart TVs, media consoles, printers, and CLI tools. The classic Authorization Code Flow assumes a rich browser for the user-agent redirect, which these devices cannot provide.

The Device Authorization Grant (RFC 8628) solves this by letting the user complete authorization on a second device (phone or laptop) while the constrained device polls for the result.

The Two Endpoints

The flow introduces a new device authorization endpoint alongside the standard token endpoint.

  • /device_authorization — the device requests codes here.
  • /token — the device polls here with grant type urn:ietf:params:oauth:grant-type:device_code.

No redirect URI is involved at all.

Step 1: Requesting Device Codes

The device makes a POST to the device authorization endpoint with its client_id and desired scope.

POST /device_authorization HTTP/1.1
Host: auth.example.com
Content-Type: application/x-www-form-urlencoded

client_id=tv-app-123&scope=profile email

Step 2: The Response

The server returns a device_code (used by the machine), a user_code (typed by the human), a verification_uri, an expires_in, and an interval for polling.

{
  "device_code": "GmRhmhcxhwAzkoEqiMEg",
  "user_code": "WDJB-MJHT",
  "verification_uri": "https://example.com/device",
  "expires_in": 900,
  "interval": 5
}

Step 3: User Instructions

The device displays a short message: Go to example.com/device and enter code WDJB-MJHT.

A verification_uri_complete may also be returned, embedding the code so a QR code can carry the whole link.

Step 4: User Authorizes

On their phone or laptop, the user opens the verification URI, logs in, enters the user_code, and approves the requested scopes. This happens in a full browser, so MFA and rich consent screens all work normally.

Step 5: Device Polls the Token Endpoint

Meanwhile the device polls the token endpoint at the given interval, sending the device_code.

POST /token HTTP/1.1
Host: auth.example.com
Content-Type: application/x-www-form-urlencoded

grant_type=urn:ietf:params:oauth:grant-type:device_code
&device_code=GmRhmhcxhwAzkoEqiMEg
&client_id=tv-app-123

Polling Responses

Until the user finishes, the server returns errors that tell the device how to behave:

  • authorization_pending — keep polling, user has not approved yet.
  • slow_down — increase the interval by 5 seconds.
  • access_denied — user rejected; stop.
  • expired_token — codes expired; restart.

Step 6: Success

Once the user approves, the next poll returns a normal token response with an access_token (and optionally a refresh_token), exactly like other grants.

{
  "access_token": "eyJhbGciOi...",
  "token_type": "Bearer",
  "expires_in": 3600,
  "refresh_token": "8xLOxBtZp8"
}

A Simple Poll Loop

A pseudo-implementation of the polling logic, respecting slow_down:

let interval = 5;
while (true) {
  await sleep(interval * 1000);
  const res = await pollToken(deviceCode);
  if (res.access_token) return res;
  if (res.error === 'slow_down') interval += 5;
  else if (res.error === 'authorization_pending') continue;
  else throw new Error(res.error);
}

Security Considerations

Keep user_codes short but high-entropy to resist brute force, and rate-limit the verification page. Because there is no redirect, phishing risk shifts to the verification URI — always show the user exactly which app and scopes they are approving.

Quick Check

Test your understanding of the device grant.

Recap

The Device Authorization Grant lets browserless devices authenticate users via a second device.

  • Device gets a device_code + user_code from the device endpoint.
  • User approves on a phone/laptop at the verification URI.
  • Device polls the token endpoint, handling authorization_pending and slow_down.
  • On approval it receives normal access and refresh tokens.

Sıkça Sorulan Sorular

“Cihaz Yetkilendirme İzni” dersi ücretsiz mi?

Evet — “Cihaz Yetkilendirme İzni” dersin tüm metni burada web'de ücretsiz olarak okunabilir. Etkileşimli olarak pratik yapmak (yerleşik kod editörü ve 7/24 yapay zeka koçu) ve OAuth2 & OpenID Connect Deep Dive kursunun geri kalanını açmak için CoddyKit PRO'ya yükselt. OAuth2 & OpenID Connect Deep Dive kursu toplamda 4 dersten oluşur.

“Cihaz Yetkilendirme İzni” dersinde ne öğreneceğim?

Akıllı televizyonlar, konsollar ve CLI araçları gibi giriş kapasitesi sınırlı cihazların ikincil bir cihaz üzerinden belirteç almasını sağlayan OAuth2 Cihaz Yetkilendirme İznini (RFC 8628) öğrenin. OAuth2 & OpenID Connect Deep Dive ile uygulamalı kodu tarayıcıda doğrudan çalıştırarak pratik yaparsın ve 7/24 yapay zeka koçu dersi çalışırken sorularını yanıtlar.

OAuth2 & OpenID Connect Deep Dive öğrenmeye başlamak için deneyim gerekli mi?

Önceden deneyim gerekmez. CoddyKit'te OAuth2 & OpenID Connect Deep Dive, başlangıçtan ileri seviyeye kadar yapılandırıldığı için buradan başlayabilir veya başından başlayıp kendi hızında ilerleme yapabilirsin. Bu, 4 dersinin 4. dersidir.

“Cihaz Yetkilendirme İzni” dersi ne kadar sürer?

Çoğu CoddyKit dersi yaklaşık 5–10 dakika sürer. Her biri kısa ve etkileşimli olduğu için sabit ilerleme yaparsın ve web ile uygulama arasında tam olarak bıraktığın yerden devam edebilirsin.

Bu OAuth2 & OpenID Connect Deep Dive dersinde kod yazıp çalıştırabilir miyim?

Evet. Her OAuth2 & OpenID Connect Deep Dive dersi yerleşik bir kod editörü içerir, bu sayede tarayıcıda gerçek kod yazıp çalıştırabilir ve anlık yapay zeka geri bildirimi alırsın — yerel kurulum gerekli değildir.

Bu kursun tüm dersleri

  1. Yetkilendirme Kodu Akışı
  2. İstemci Kimlik Bilgileri Akışı
  3. Örtük Akış ve Kullanımdan Kaldırılması
  4. Cihaz Yetkilendirme İzni
← OAuth2 & OpenID Connect Deep Dive Sayfasına Dön