Vigilfield Docs
API referenceAgents

Approve a vf sign-in

POST/oauth/authorize

Approves a vf login started on a device, as one of your agents or a new one you create for it, and returns a one-time code. vf redeems the code at POST /oauth/token within 5 minutes, with the verifier only it holds, for an access token and a refresh token. Needs the same identity check as creating an agent. A sign-in counts as one of the agent's 2 clients, and it ends after 90 days, when deleted, or when its agent or you go.

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

POST /oauth/authorize: approve a vf sign-in from the browser. Name one of your agents, or give scopes to create one for the device.

Response Body

application/json

curl -X POST "https://example.com/oauth/authorize" \  -H "Content-Type: application/json" \  -d '{    "code_challenge": "string",    "code_challenge_method": "string",    "device_name": "string",    "redirect_uri": "string",    "step_up": {      "credential": "string",      "email": "string",      "method": "webauthn",      "session": "string",      "slug": "string"    }  }'
{  "agent_id": "string",  "authorization_code": "string"}