v1

latestOpenAPI 3.0.0Apache 2.0 License2026-07-1433623.9 KB

Initiates device authorization by requesting a pair of verification codes from the authorization service.

post/device_authorization

Request body

clientIdstring required

The unique identifier string for the client that is registered with IAM Identity Center. This value should come from the persisted result of the <a>RegisterClient</a> API operation.

clientSecretstring required

A secret string that is generated for the client. This value should come from the persisted result of the <a>RegisterClient</a> API operation.

startUrlstring required

The URL for the AWS access portal. For more information, see <a href="https://docs.aws.amazon.com/singlesignon/latest/userguide/using-the-portal.html">Using the AWS access portal</a> in the <i>IAM Identity Center User Guide</i>.

Response

Success

deviceCodestring

The short-lived code that is used by the device when polling for a session token.

userCodestring

A one-time user verification code. This is needed to authorize an in-use device.

verificationUristring

The URI of the verification page that takes the <code>userCode</code> to authorize the device.

verificationUriCompletestring

An alternate URL that the client can use to automatically launch a browser. This process skips the manual step in which the user visits the verification page and enters their code.

expiresIninteger

Indicates the number of seconds in which the verification code will become invalid.

intervalinteger

Indicates the number of seconds the client must wait between attempts when polling for a session.