Approve a vf sign-in
/oauth/authorizeApproves a vf login started on a device, as one of your agents or a new one you create for it, and returns a one-time code. vf redeems the code at POST /oauth/token within 5 minutes, with the verifier only it holds, for an access token and a refresh token. Needs the same identity check as creating an agent. A sign-in counts as one of the agent's 2 clients, and it ends after 90 days, when deleted, or when its agent or you go.
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
POST /oauth/authorize: approve a vf sign-in from the browser. Name one of your agents, or give scopes to create one for the device.
Response Body
application/json
curl -X POST "https://example.com/oauth/authorize" \ -H "Content-Type: application/json" \ -d '{ "code_challenge": "string", "code_challenge_method": "string", "device_name": "string", "redirect_uri": "string", "step_up": { "credential": "string", "email": "string", "method": "webauthn", "session": "string", "slug": "string" } }'{ "agent_id": "string", "authorization_code": "string"}