Spring Security Device API

The Device API from Spring Security — 1 operation(s) for device.

OpenAPI Specification

spring-security-device-api-openapi.yml Raw ↑
openapi: 3.0.3
info:
  title: Spring Server Authorization Device API
  description: Spring Authorization Server is a framework providing implementations of OAuth 2.1 and OpenID Connect 1.0 specifications. It exposes standard protocol endpoints for token issuance, token introspection, JWKS publication, device authorization, and OpenID Connect session management.
  version: 1.3.0
  contact:
    name: Spring Security Team
    url: https://spring.io/projects/spring-authorization-server
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0
servers:
- url: http://localhost:9000
  description: Default authorization server port
tags:
- name: Device
paths:
  /oauth2/device_authorization:
    post:
      operationId: deviceAuthorization
      summary: Device Authorization Request
      description: Initiates the OAuth 2.0 Device Authorization Grant per RFC 8628
      tags:
      - Device
      requestBody:
        required: true
        content:
          application/x-www-form-urlencoded:
            schema:
              type: object
              properties:
                client_id:
                  type: string
                scope:
                  type: string
      security:
      - basicAuth: []
      responses:
        '200':
          description: Device authorization response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DeviceAuthorizationResponse'
components:
  schemas:
    DeviceAuthorizationResponse:
      type: object
      properties:
        device_code:
          type: string
        user_code:
          type: string
        verification_uri:
          type: string
        verification_uri_complete:
          type: string
        expires_in:
          type: integer
        interval:
          type: integer
  securitySchemes:
    basicAuth:
      type: http
      scheme: basic
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT