v16

OpenAPI 3.0.3Apache 2.0raw.githubusercontent.com2026-04-0886158866.0 KB
Device Flow

Complete Device Authorization

This API returns information about what action the authorization server should take after it receives the result of end-user's decision about whether the end-user has approved or rejected a client application's request.

post/api/{serviceId}/device/complete

Path parameters

serviceIdstring required

A service ID.

Request body

userCodestring required

A user code.

result'TRANSACTION_FAILED' | 'ACCESS_DENIED' | 'AUTHORIZED' required

The result of the end-user authentication and authorization. One of the following. Details are described in the description.

subjectstring required

The subject (= unique identifier) of the end-user.

substring

The value of the sub claim that should be used in the ID token.

authTimeinteger

The time at which the end-user was authenticated. Its value is the number of seconds from 1970-01-01.

acrstring

The reference of the authentication context class which the end-user authentication satisfied.

claimsstring

Additional claims which will be embedded in the ID token.

scopesstring[]

Scopes to replace the scopes specified in the original device authorization request with. When nothing is specified for this parameter, replacement is not performed.

errorDescriptionstring

The description of the error. If this optional request parameter is given, its value is used as the value of the error_description property, but it is used only when the result is not AUTHORIZED. To comply with the specification strictly, the description must not include characters outside the set %x20-21 / %x23-5B / %x5D-7E.

errorUristring

The URI of a document which describes the error in detail. This corresponds to the error_uri property in the response to the client.

idtHeaderParamsstring

JSON that represents additional JWS header parameters for ID tokens.

consentedClaimsstring[]

the claims that the user has consented for the client application to know.

jwtAtClaimsstring

Additional claims that are added to the payload part of the JWT access token.

accessTokenDurationinteger

The duration (in seconds) of the access token that may be issued as a result of the Authlete API call.

When this request parameter holds a positive integer, it is used as the duration of the access token in. In other cases, this request parameter is ignored.

refreshTokenDurationinteger

The duration (in seconds) of the refresh token that may be issued as a result of the Authlete API call.

When this request parameter holds a positive integer, it is used as the duration of the refresh token in. In other cases, this request parameter is ignored.

idTokenAudTypestring

The type of the aud claim of the ID token being issued. Valid values are as follows.

ValueDescription
"array"The type of the aud claim is always an array of strings.
"string"The type of the aud claim is always a single string.
nullThe type of the aud claim remains the same as before.

This request parameter takes precedence over the idTokenAudType property of the service.

Response

resultCodestring

The code which represents the result of the API call.

resultMessagestring

A short message which explains the result of the API call.

action'SERVER_ERROR' | 'USER_CODE_NOT_EXIST' | 'USER_CODE_EXPIRED' | 'INVALID_REQUEST' | 'SUCCESS'

The next action that the authorization server implementation should take.