You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

无头设备OAuth2认证:自定义user_code设置位置及示例教程咨询

Headless Device OAuth2: Where to Use the user_code with Your Verification URL

Let's walk through exactly how to handle the user_code in your headless device OAuth2 flow, especially using the "Optimization for Non-Textual Interfaces" approach.

First, Understand the Flow Basics

The user_code isn't something you "set" manually—it's generated by your authorization server and returned to your device during the initial device authorization request. Your job is to surface this code to the end user, and direct them to the verification URL (like the one you provided: https://authorization-server.com/device?user_code=BDWD-HQPK) to complete the auth step.

Step-by-Step Example

1. Request Device Credentials from the Authorization Server

First, your headless device needs to call the server's device authorization endpoint to get the user_code, device_code, and verification URLs. Here's a curl example (you can adapt this to your device's programming language):

curl -X POST https://authorization-server.com/oauth2/device_authorization \
  -H "Content-Type: application/x-www-form-urlencoded" \
  -d "client_id=YOUR_CLIENT_ID&scope=openid%20profile%20your-required-scopes"

You'll get a JSON response like this (note the user_code and pre-built verification_uri_complete which matches your URL):

{
  "device_code": "abc123xyz",
  "user_code": "BDWD-HQPK",
  "verification_uri": "https://authorization-server.com/device",
  "verification_uri_complete": "https://authorization-server.com/device?user_code=BDWD-HQPK",
  "expires_in": 1800,
  "interval": 5
}

2. Display the Code and Verification URL to the User

Since this is a headless device, you'll need to output this info via whatever interface you have:

  • Print it to a serial console
  • Show it on an attached small display
  • Send it to a paired mobile app (if you have that integration)

Tell the user:

"Open this URL in a browser on another device: https://authorization-server.com/device?user_code=BDWD-HQPK
Enter the code: BDWD-HQPK
Log in with your account to authorize this device."

3. Poll the Token Endpoint to Get Your Access Token

While the user is completing the browser step, your headless device needs to repeatedly poll the authorization server's token endpoint using the device_code (not the user_code) to check if authorization is complete. Use the interval value from the initial response to avoid spamming the server:

# Wait 5 seconds between polls (match the "interval" from the response)
sleep 5

curl -X POST https://authorization-server.com/oauth2/token \
  -H "Content-Type: application/x-www-form-urlencoded" \
  -d "grant_type=urn:ietf:params:oauth:grant-type:device_code&device_code=abc123xyz&client_id=YOUR_CLIENT_ID"

When the user finishes authorizing, you'll get a response with your access token:

{
  "access_token": "eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9...",
  "token_type": "Bearer",
  "expires_in": 3600,
  "refresh_token": "def456uvw"
}

Key Notes for Non-Textual Interfaces

The "Optimization for Non-Textual Interfaces" section likely emphasizes making the user's job as easy as possible:

  • Use the verification_uri_complete (the pre-built URL with user_code included) so the user doesn't have to manually type the code—some servers will auto-fill it when the URL is opened.
  • If your device has no way to display text, you might use a QR code that encodes the verification_uri_complete—users can scan it with their phone to open the URL directly.

内容的提问来源于stack exchange,提问作者Roel Alblas

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.21 03:50:14