iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
OAuth 2.0 device flow lets an internet-connected device with limited input—such as a TV or printer—request access while you sign in and approve the request in a browser on a phone or computer. The original device then retrieves the result by polling the authorization server; your phone does not send a token directly to the TV.
How does OAuth device flow work?
OAuth 2.0 Device Authorization Grant, commonly called device flow or device-code flow, is designed for devices that lack a suitable browser or practical way to enter credentials. The device needs an internet connection, a way to show you a web address and code, and access to the authorization server. You use a second, browser-capable device to complete sign-in and approval. The protocol is not intended to replace browser-based OAuth on a capable device. See RFC 8628.
- You start the request on the device. The client contacts the authorization server with its identity and, where applicable, the requested access scope. The standard says a client should not launch this flow automatically at app startup or repeatedly after failure; it should begin when the user is ready.
- The server returns two different codes. The device receives a high-entropy
device_codefor its later token request, a shorteruser_codefor you to enter, averification_uri, an expiry time, and a polling interval. The device code is for the client’s back-channel request; it should not be displayed to you. - You open the verification page. The device displays the address and user code, and asks you to visit the address on another device. Some servers also return
verification_uri_complete, which can support a QR-code or similar shortcut. A shortcut changes how you reach the authorization page, not what you should verify before approving. - You authenticate and decide whether to approve. The authorization server checks the user code, authenticates you, and presents the request. The exact screens and wording depend on the provider. Approve only if the request matches the device and service you intended to connect.
- The original device polls for the result. While you complete the browser step, the device sends token requests using its device code and the device-code grant type. Once authorization succeeds, the token endpoint returns the token response to that device.
- The client follows the server’s response.
authorization_pendingmeans wait and try again at the required interval.slow_downmeans add five seconds to the wait for that and all subsequent polling requests.access_deniedandexpired_tokenare terminal: stop polling. Other error responses also require polling to stop. If a request times out at the connection level, the client must reduce its polling frequency; exponential backoff is recommended.
In short, the device requests authorization, you approve on a second device, and the original device learns the outcome by polling the authorization server.
Recommended Free Tools
Why is my TV asking me to enter a code on another device?
The TV likely has a network connection but lacks a convenient way to enter a password or complete a browser-based sign-in. Device flow moves the interactive part to a phone or computer, where typing and authentication are easier. After you approve, the TV checks with the server and receives its own token response.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
This is a normal pattern for constrained devices, but the presence of a real sign-in page does not prove that the request came from your TV. Someone else can start a device authorization request and persuade you to enter their code at a genuine provider website. You could authenticate successfully and still authorize the wrong device.
- Start the flow yourself from the TV or app you intend to connect; do not enter a code supplied unexpectedly in a message, call, pop-up, or unrelated website.
- Check the device name, app, account, and requested access shown by the authorization page. Stop if the details do not match what is in front of you or what you meant to authorize.
- Do not treat a QR code or prefilled verification link as proof of legitimacy. It can make code entry easier, but the device and requested access still need checking.
- If you did not initiate the request, deny it or let it expire rather than approving it to dismiss a prompt.
RFC 8628 recommends telling users that they are authorizing a device and asking them to confirm it is in their possession. It also calls for user-code attempt rate limits and careful handling of code entropy, lifetime, and visibility to people nearby.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
What security guidance applies to cross-device sign-in?
Device flow is useful precisely because sign-in moves across devices, and that handoff creates risks such as phishing and session-transfer attacks. RFC 10027, an IETF Best Current Practice published in August 2026, covers device authorization among other cross-device flows. It says implementers must assess risks before implementation, should avoid the flow if identified risks cannot be sufficiently mitigated, and must select suitable mitigations. It also recommends using proximity as a mitigation when possible. This is security guidance for designing cross-device flows, not a replacement for RFC 8628.
At a broader OAuth level, RFC 9700, published in January 2025, recommends sender-constraining access tokens—for example, with mutual TLS or DPoP—to reduce the risk of misuse if tokens are stolen or leaked. That recommendation applies beyond device flow.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
When should an app use device flow instead of browser sign-in?
Use device authorization when the client is internet-connected but lacks a suitable browser or usable input method. If the device can securely perform a browser-based authorization flow itself, RFC 8628 says device flow should not displace that option. The trade-off is practical: moving sign-in elsewhere can make access possible on constrained hardware, but the cross-device handoff needs safeguards against approving a request started by someone else.
For implementers, the main protocol choices are the user experience and the polling behavior: explain the verification step clearly, help users identify the device they are authorizing, and honor the server’s interval, retry, and stop responses. A complete verification URI or QR code can reduce typing, but does not remove the need for device confirmation.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
How does Microsoft Entra implement device authorization?
Microsoft Entra documents a device-code request to a /devicecode endpoint followed by polling the /token endpoint. Its documentation gives a default expires_in period of 15 minutes; that is a Microsoft implementation detail, not a universal device-flow lifetime. Microsoft recommends using its supported Microsoft Authentication Libraries (MSAL) where possible. See Microsoft’s device code flow documentation.
For operations teams, Microsoft says successful device-code flow events in environments without a corresponding business need should be investigated. Entra sign-in logs are one monitoring source, and Conditional Access can be configured to block or allow device-code flow. The relevant policies and interfaces depend on the tenant and can change; consult the current Microsoft guidance on blocking authentication flows.
Quick Recap
Best Value
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

