Device sign-in
Device sign-in lets a game sign a player in without a browser or keyboard. The game shows a short code, the player approves it on another device, and the game polls until it receives tokens.
The flow
- The game asks for a device authorization with its client ID and scopes.
openidis required, andoffline_accessadds a refresh token if the application allows it. - auth4.dev returns an 8-character
user_code(letters and digits), a verification URL on the auth origin, and adevice_codethat only the game sees. The code expires after10 minutes. - The player opens the verification URL on a phone or computer, checks that the application name and code match, and selects approve or deny. Opening the link alone never approves anything.
- The game polls the token endpoint until the player decides or the code expires.
The player must already be signed in to auth4.dev in that browser. Approval grants exactly the scopes the game asked for; the approval page can't add scopes.
Polling rules
| Response | What the game should do |
|---|---|
authorization_pending | Wait the current interval (5 seconds to start), then poll again. |
slow_down | You polled too early. Add 5 seconds to the interval and keep the longer interval from now on. |
access_denied | The player declined. Stop polling and offer to start again. |
expired_token | The 10 minutes are up. Stop, and start a new authorization with a new code. |
| Tokens | Signed in. The device code can't be redeemed again. |
| Network error or 5xx | Back off and retry within the code's lifetime. Don't start a new code for a brief outage. |
In Unity
The Unity SDK implements these rules. SignInWithDeviceAsync does everything in one call. For more control, use StartDeviceAuthorizationAsync andPollDeviceAuthorizationAsync:
- It waits at least the server's interval (minimum five seconds) before every poll.
- It adds five seconds on each
slow_down, and backs off on network and server errors. It gives up afterMaxConsecutiveTransientPollFailuresconsecutive failures (default 5). - It stops at the code's expiry or after
MaxDevicePollAttemptspolls (default 240). - Cancelling throws
OperationCanceledException. You can resume the same authorization withPollDeviceAuthorizationAsyncuntil it expires, which is useful when the player closes and reopens a menu. - It rejects verification URLs that don't belong to the configured auth origin.
See the Unity quickstart for code.
Custom clients
Other engines can call the endpoints directly. The console's integration settings show both requests, already filled in for your application:
POST https://auth.auth4.dev/device/authorization?tenant_id={projectId}
Content-Type: application/x-www-form-urlencoded
client_id={clientId}&scope=openid%20offline_access
POST https://auth.auth4.dev/oauth/token?tenant_id={projectId}
Content-Type: application/x-www-form-urlencoded
grant_type=urn%3Aietf%3Aparams%3Aoauth%3Agrant-type%3Adevice_code&device_code={device_code}&client_id={clientId}Use fixed endpoint paths. The discovery document doesn't list the device endpoint yet. Full details are in the device authorization reference.
Good on-screen practice
- Show the code in a large monospace font. Codes use only capital letters and digits.
- Show the verification address in full, and a QR code of the complete URL if you can.
- Show a countdown to expiry and a cancel button.
- Tell the player which application name to expect on the approval page.