> ## Documentation Index
> Fetch the complete documentation index at: https://docs.orbitlab.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Poll a CLI device login

> Until approved, responds 400 with `error` set to `authorization_pending`. Other errors: `slow_down` (poll 5 seconds less often), `temporarily_unavailable` (retry), `access_denied`, `expired_token`, `invalid_grant`. Once approved, returns the API token exactly once.

CLI: `orbitlab login`



## OpenAPI

````yaml /api-reference/openapi.json post /v1/auth/device/token
openapi: 3.1.0
info:
  title: OrbitLab API
  version: 1.0.0
  description: >-
    Manage OrbitLab services, deployments, domains, DNS, databases,
    organizations and billing programmatically. Authenticate with an API token:
    `Authorization: Bearer olab_…`.
servers:
  - url: https://orbitlab.dev/api
    description: Production
security: []
tags:
  - name: Authentication
    description: CLI device login.
  - name: User
    description: The authenticated user and their API tokens.
  - name: Organizations
    description: Organizations, members and invitations.
  - name: Catalog
    description: Plans and deployable templates.
  - name: Services
    description: 'Apps, WordPress sites and VPS: configuration, deployments and environment.'
  - name: Logs & metrics
    description: Build logs, runtime logs, request logs and resource usage.
  - name: Service domains
    description: Custom domains attached to a service.
  - name: Files
    description: File manager and SFTP access.
  - name: WordPress
    description: Managed actions (WP-CLI) and admin reset.
  - name: Hostings
    description: Shared hosting subscriptions and their websites.
  - name: Domains
    description: Domain registration, settings and DNS records.
  - name: Databases
    description: Managed databases.
  - name: Billing
    description: Checkout, orders, invoices, renewals and autopay.
  - name: GitHub
    description: GitHub App installations and repositories.
paths:
  /v1/auth/device/token:
    post:
      tags:
        - Authentication
      summary: Poll a CLI device login
      description: >-
        Until approved, responds 400 with `error` set to
        `authorization_pending`. Other errors: `slow_down` (poll 5 seconds less
        often), `temporarily_unavailable` (retry), `access_denied`,
        `expired_token`, `invalid_grant`. Once approved, returns the API token
        exactly once.


        CLI: `orbitlab login`
      operationId: postAuthDeviceToken
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                deviceCode:
                  type: string
                  description: The device code from the start endpoint.
              required:
                - deviceCode
      responses:
        '200':
          description: >-
            `token` (expires after 90 days), `tokenId`, `expiresAt`,
            `organizationId`, `user.email`.
          content:
            application/json:
              schema:
                type: object
        '400':
          description: Invalid request.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '429':
          description: Rate limited; see the Retry-After header.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security: []
components:
  schemas:
    Error:
      type: object
      properties:
        error:
          description: Error message (a string, or field errors for validation failures).
      required:
        - error

````