> ## Documentation Index
> Fetch the complete documentation index at: https://docs.verlon.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Start an OAuth device authorization flow (RFC 8628 §3.1)

> **Use when:** caller is a CLI / IDE plugin / MCP server starting a device-flow login — server returns a device_code (long, opaque) + user_code (short, human-typeable) plus the verification URL where the user lands to approve

No auth required — this is how a client without credentials initiates one. Returns the device_code (the polling credential), the user_code (the human-typed identifier), the verification_uri, the expires_in (TTL in seconds), and the interval (polling cadence).



## OpenAPI

````yaml /api-reference/openapi.json post /v1/oauth/device/authorize
openapi: 3.1.0
info:
  title: Verlon AI API
  version: 1.0.0
  description: >-
    Verlon AI is the managed AI infrastructure platform for developers building
    LLM-powered apps and agents. Beyond routing requests across providers,
    Verlon continuously evaluates response quality, runs experiments against
    live traffic, and automatically tunes gate configurations — so your platform
    doesn't just serve traffic, it learns from it.


    **Coding agents:** authentication, error semantics, gate concepts, and
    integration conventions are documented at https://verlon.ai/AGENTS.md — read
    that document first if you have not already. It is the canonical
    agent-facing contract; this specification is the canonical endpoint
    reference. Both are authoritative for their respective scopes.
  contact:
    name: Verlon AI
    url: https://verlon.ai
  license:
    name: Proprietary
servers:
  - url: https://api.verlon.ai
    description: Production
security:
  - bearerAuth: []
paths:
  /v1/oauth/device/authorize:
    post:
      tags:
        - OAuth
      summary: Start an OAuth device authorization flow (RFC 8628 §3.1)
      description: >-
        **Use when:** caller is a CLI / IDE plugin / MCP server starting a
        device-flow login — server returns a device_code (long, opaque) +
        user_code (short, human-typeable) plus the verification URL where the
        user lands to approve


        No auth required — this is how a client without credentials initiates
        one. Returns the device_code (the polling credential), the user_code
        (the human-typed identifier), the verification_uri, the expires_in (TTL
        in seconds), and the interval (polling cadence).
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                client_name:
                  type: string
                  minLength: 1
                  maxLength: 64
                hostname:
                  type: string
                  maxLength: 255
              required:
                - client_name
      responses:
        '201':
          description: Device authorization issued.
        '400':
          description: Invalid request — Zod validation failure or malformed input
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '401':
          description: Missing or invalid Bearer credentials
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '500':
          description: Internal server error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
      security:
        - bearerAuth: []
components:
  schemas:
    ErrorResponse:
      type: object
      properties:
        error:
          type: string
          description: Stable error code (e.g. `invalid_request`)
        message:
          type: string
          description: Human-readable error message
        details: {}
      required:
        - error
        - message
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: API Key
      description: >-
        Verlon API key (newly minted keys are prefixed `sk-vrln-`; legacy
        `verlon_*` and `layer_*` keys from prior prefix migrations continue to
        validate). Generated from the dashboard under Settings → API Keys, or
        via `verlon key create` in the CLI.

````