# OAuth 2.0 Device Authorization Grant

**URL:** <https://forum.keycloak.org/t/oauth-2-0-device-authorization-grant/8890>\
**Category:** Getting advice\
**Created:** [May 4, 2021, 1:28pm UTC](https://forum.keycloak.org/t/oauth-2-0-device-authorization-grant/8890 "2021-05-04T13:28:25Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![sebastienm](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/sebastienm/32/295_2.png) [@sebastienm](https://forum.keycloak.org/u/sebastienm)\
**Post date:** [May 4, 2021, 1:28pm UTC](https://forum.keycloak.org/t/oauth-2-0-device-authorization-grant/8890/1 "2021-05-04T13:28:25Z")

</div>

Hi there,

We have new need in the organisation and we have to provide device authorization flow for device on with input is complex.

the flow is described here : [keycloak-community/oauth2-device-authorization-grant.md at master · keycloak/keycloak-community · GitHub](https://github.com/keycloak/keycloak-community/blob/master/design/oauth2-device-authorization-grant.md)

But I can’t find any official doc about it. Is it implemented, plan to be or … ?

any help is much appreciated

have a good day

---

<div class="post-metadata">

**Author:** ![sebastienm](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/sebastienm/32/295_2.png) [@sebastienm](https://forum.keycloak.org/u/sebastienm)\
**Post date:** [May 13, 2021, 9:39am UTC](https://forum.keycloak.org/t/oauth-2-0-device-authorization-grant/8890/2 "2021-05-13T09:39:17Z")

</div>

Ok seems I’m kind of lucky, this flow is available in keycloak 13.0 released last week 🙂

---

<div class="post-metadata">

**Author:** ![sebastienm](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/sebastienm/32/295_2.png) [@sebastienm](https://forum.keycloak.org/u/sebastienm)\
**Post date:** [May 25, 2021, 7:47am UTC](https://forum.keycloak.org/t/oauth-2-0-device-authorization-grant/8890/3 "2021-05-25T07:47:54Z")

</div>

Or maybe not so lucky as it seems to be implemented but yet there is no documentation.

---

<div class="post-metadata">

**Author:** ![xgp](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/xgp/32/2589_2.png) [@xgp](https://forum.keycloak.org/u/xgp)\
**Post date:** [May 25, 2021, 8:45am UTC](https://forum.keycloak.org/t/oauth-2-0-device-authorization-grant/8890/4 "2021-05-25T08:45:23Z")

</div>

There is no official documentation yet (“We need to add explanation about supporting the spec into keycloak-documentation”), but the “How to try it” ([keycloak-community/oauth2-device-authorization-grant.md at master · keycloak/keycloak-community · GitHub](https://github.com/keycloak/keycloak-community/blob/master/design/oauth2-device-authorization-grant.md#how-to-try-it)) section in the doc gives decent instructions. Have you tried that? I went through it with Keycloak 13, and everything works. Let us know if you have specific questions.

---

<div class="post-metadata">

**Author:** ![ericfer](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/ericfer/32/3229_2.png) [@ericfer](https://forum.keycloak.org/u/ericfer)\
**Post date:** [May 27, 2021, 10:16am UTC](https://forum.keycloak.org/t/oauth-2-0-device-authorization-grant/8890/5 "2021-05-27T10:16:23Z")

</div>

Hi, i have this issue.  
I cant enable `OAuth 2.0 Device Grant Enabled` as a public client only as private.  
How do i enable it as public ?  
I’m on ver 13

---

<div class="post-metadata">

**Author:** ![A\_Random\_Dude](https://avatars.discourse-cdn.com/v4/letter/a/8dc957/32.png) [@A\_Random\_Dude](https://forum.keycloak.org/u/A_Random_Dude)\
**Post date:** [November 2, 2021, 1:28pm UTC](https://forum.keycloak.org/t/oauth-2-0-device-authorization-grant/8890/6 "2021-11-02T13:28:18Z")

</div>

It may help if someone is looking for this thread  
For Device flow

If you have Access Type set as public then you can use the device end point without client secret  
curl --location --request POST ‘[http://localhost:8080/auth/realms/Communi5/protocol/openid-connect/auth/device](http://localhost:8080/auth/realms/Communi5/protocol/openid-connect/auth/device)’   
–data-urlencode ‘client\_id=c5client’

However, if you have the Access Type set as confidential then you need to specify the client secret as well.

These settings are available in Clients page of keycloak.

---

<div class="post-metadata">

**Author:** ![cobar79](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/cobar79/32/10368_2.png) [@cobar79](https://forum.keycloak.org/u/cobar79)\
**Post date:** [May 8, 2024, 4:20pm UTC](https://forum.keycloak.org/t/oauth-2-0-device-authorization-grant/8890/7 "2024-05-08T16:20:11Z")

</div>

Docker server version 23.0.7  
I am receiving 405 on the “Device Authorization Endpoint” with or without the client authorization. I can’t find any reference to “Access Type”.

```auto
curl -X POST \
    -d "client_id=osint-client" \
    "http://localhost:9080/realms/osint-realm/protocol/openid-connect/device/auth"

```

I would also like to confirm whether the client device is a 1-1 or 1-Many association.

![image](https://global.discourse-cdn.com/free1/uploads/keycloak/original/2X/6/6611a24b90e2553367edb6a1a49bb3358aea2cac.png)

---

<div class="post-metadata">

**Author:** ![mbonn](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/mbonn/32/5755_2.png) [@mbonn](https://forum.keycloak.org/u/mbonn)\
**Post date:** [May 10, 2024, 7:10am UTC](https://forum.keycloak.org/t/oauth-2-0-device-authorization-grant/8890/8 "2024-05-10T07:10:53Z")

</div>

“Access Type” refers to the old admin console. In the new one, it’s the “Client authentication” switch that changes between public (OFF) and confidential client (ON). If you have it set to ON (that’s necessary to enable the Service account grant) to have to add client\_secret=[Secret] to your device flow http requests.

The first request of the device and the user authentication with the code have to call the device endpoint (…/openid-connect/auth/device), but then the token has to be queried by the device at the standard token endpoint 8…/openid-connect/token)
