{"record":{"id":"da383df566ebaab2","repo":"JuliusBrussee/caveman","slug":"device-authorization-failed-http-coderesp-statu","errorCode":null,"errorMessage":"device authorization failed: HTTP ${codeResp.status}","messagePattern":"device authorization failed: HTTP (.+?)","errorType":"http","errorClass":null,"httpStatus":null,"severity":"error","filePath":"packages/cli/src/index.ts","lineNumber":9681,"sourceCode":"// from the returned token, never from any local input.\n// Hosted login remains gated; explicit private instances use project access.\nfunction blockCloudLoginWhileBeta(): void {\n  throw new Error(\"Caveman Cloud platform is still in beta.\");\n}\n\nasync function login(argv: string[] = []) {\n  if (!argv.some((arg) => arg === \"--instance\" || arg.startsWith(\"--instance=\"))) blockCloudLoginWhileBeta();\n  const { noBrowser, instance } = validateLoginArgs(argv);\n  const baseURL = instance ?? resolveLoginBaseUrl(argv);\n\n  const codeResp = await fetch(`${baseURL}/api/v1/auth/device/code`, {\n    method: \"POST\",\n    redirect: \"error\",\n    headers: { \"content-type\": \"application/json\" },\n    body: \"{}\",\n    signal: AbortSignal.timeout(5000),\n  });\n  if (!codeResp.ok) throw new Error(`device authorization failed: HTTP ${codeResp.status}`);\n  const code = await codeResp.json();\n  if (!code.device_code) throw new Error(\"device authorization failed: missing device code\");\n\n  const verificationURL = instance ? privateVerificationURL(code, instance) : code.verification_uri_complete ?? code.verification_uri;\n  console.error(`\\n  Authorize this device in your browser:`);\n  console.error(`    ${verificationURL}`);\n  console.error(`    code: ${code.user_code}\\n`);\n  if (typeof verificationURL === \"string\" && shouldOpenLoginBrowser(noBrowser)) openLoginBrowser(verificationURL);\n\n  let intervalMs = Math.max(0, Number(code.interval ?? 5)) * 1000;\n  const deadline = Date.now() + Number(code.expires_in ?? 600) * 1000;\n  while (Date.now() < deadline) {\n    let tok: Record<string, unknown>;\n    let tokenStatus = 0;\n    let retryAfterMs = 0;\n    try {\n      const tokResp = await fetch(`${baseURL}/api/v1/auth/device/token`, {\n        method: \"POST\",","sourceCodeStart":9663,"sourceCodeEnd":9699,"githubUrl":"https://github.com/JuliusBrussee/caveman/blob/3ee70a102609e550bd2e68004bf5990a9341c851/packages/cli/src/index.ts#L9663-L9699","documentation":"The CLI starts the RFC 8628 device-authorization flow by POSTing to the instance's device/code endpoint. If the HTTP response is not ok, it cannot obtain a device code and throws with the status code. This is a fail-fast check before any polling begins.","triggerScenarios":"The POST to the device authorization endpoint returns a non-2xx status (401 wrong client/audience, 404 wrong path, 429 rate limit, 5xx server error) within the 5s AbortSignal timeout window.","commonSituations":"Wrong --instance URL pointing at a host without the device-code endpoint; identity provider misconfigured (missing device grant); server outage; rate limiting from repeated login attempts.","solutions":["Check the printed status code: 404 usually means wrong instance/base URL, 401 a client misconfiguration, 429 too many attempts","Verify the --instance URL points at the correct authorization server with the device-code endpoint enabled","Wait and retry if the status is 429 or 5xx","Inspect instance/server logs for the failing request"],"exampleFix":"// before\nawait cli.login({ instance: \"https://wrong-host.example.com\" });\n// after\nawait cli.login({ instance: \"https://auth.correct-instance.example.com\" });","handlingStrategy":"retry","validationCode":"const probe = await fetch(new URL(\"/oauth/device/code\", instance), { method: \"HEAD\" }).catch(() => null);\nif (!probe || !probe.ok && probe.status !== 405) console.warn(\"Device-code endpoint not reachable at instance\");","typeGuard":null,"tryCatchPattern":"try { await login({ instance }) } catch (e) { const m = e.message.match(/HTTP (\\d+)/); if (m && (m[1] === \"429\" || m[1].startsWith(\"5\"))) await backoffThenRetry(); }","preventionTips":["Verify the instance URL exposes the device-code endpoint before automating logins","Back off on 429 instead of hammering login","Monitor authorization-server health"],"tags":["http","oauth","device-flow","network"],"backgroundTag":"http-error-response","analyzedSha":"3ee70a102609e550bd2e68004bf5990a9341c851","analyzedAt":"2026-09-20T15:53:39.229Z","contentChangedAt":"2026-09-20T15:53:39.229Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}