> ## Documentation Index
> Fetch the complete documentation index at: https://docs.antigen.sh/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Start device login

> Start the CLI login flow and return a URL and code for browser approval.



## OpenAPI

````yaml /api/openapi.yaml post /auth/device-code
openapi: 3.1.0
info:
  title: Antigen API
  version: v1
  description: >-
    Use the Antigen API to manage targets, runs, vulnerabilities, evidence,
    reports, hooks, assets, and integrations.
servers:
  - url: https://api.antigen.sh/v1
    description: Production
security:
  - ApiKeyAuth: []
  - BearerAuth: []
  - SessionCookie: []
tags:
  - name: Authentication
  - name: API keys
  - name: Models
  - name: Agents
  - name: Targets
  - name: Runs
  - name: Vulnerabilities
  - name: Evidence
  - name: Reports
  - name: Hooks
  - name: Asset Map
  - name: Integrations
paths:
  /auth/device-code:
    post:
      tags:
        - Authentication
      summary: Start device login
      description: Start the CLI login flow and return a URL and code for browser approval.
      operationId: startDeviceLogin
      responses:
        '200':
          description: Device login started.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DeviceCodeResponse'
      security: []
components:
  schemas:
    DeviceCodeResponse:
      type: object
      required:
        - device_code
        - user_code
        - verification_url
        - expires_in
        - interval
      properties:
        device_code:
          type: string
        user_code:
          type: string
        verification_url:
          type: string
          format: uri
        expires_in:
          type: number
        interval:
          type: number
  securitySchemes:
    ApiKeyAuth:
      type: apiKey
      in: header
      name: x-api-key
      description: API key from the Antigen dashboard.
    BearerAuth:
      type: http
      scheme: bearer
      bearerFormat: access token
      description: Better Auth access token.
    SessionCookie:
      type: apiKey
      in: cookie
      name: better-auth.session_token
      description: Better Auth browser session cookie.

````