# Device Login (Notchset): prompt.md (v1.0.0)

- id: `device-auth` · version 1.0.0 · block · pro (Pro)
- category: Application UI
- build: Base UI (one set of files; its dependencies follow the build)
- install (this build): `npx shadcn@latest add @beautiful-ui-pro/device-auth`
- npm dependencies: class-variance-authority@^0.7
- registry dependencies: utils, @beautiful-ui/segmented-control, https://beautiful-ui.dev/r/notchset-foundation.json
- docs: https://beautiful-ui.dev/components/device-auth
- The install command carries everything this item needs (files, CSS, tokens, npm and registry dependencies). Prefer it to copying source by hand.

OAuth device login for a CLI with the terminal and the browser side by side: the browser takes the code (formatted XXXX-XXXX, with a phishing guard), shows the device, a workspace and least-privilege scopes where a dangerous scope is off by default and warns when on, then authorizes or denies while the terminal answers in the same moment; the request expires on a rolling clock.

## Build it
- Stack: React 19 (`ref` is a plain prop), TypeScript, Tailwind CSS v4 utilities, a shadcn-initialised project with the `@/*` alias.
- Packages: `class-variance-authority@^0.7`.
- Files: `components/ui/notchset/blocks/device-auth.tsx`; shared code: `lib/beautiful-ui/notchset/instrument.tsx`, `lib/beautiful-ui/notchset/root.ts`, `lib/beautiful-ui/notchset/button-variants.ts`.
- Registry dependencies, installed with it automatically: shadcn `utils` (cn), `segmented-control`, `notchset-foundation`.
- Builds: one set of files for both, but its dependencies come in Base UI and Radix builds. Install the one that matches the project (see Install): a free item's bare URL installs the Base UI build of it and its dependencies.
- Exports to keep: `DeviceAuth`, and every exported type.
- CSS: the install adds the notchset foundation (tokens, keyframes, motion levels) to your global stylesheet once. Nothing to import by hand.
- Re-running `add` (or `--overwrite`) re-applies those rules: put overrides in your own CSS, never in the installed rules.
- Tokens: retheme with the `--notchset-*` custom properties (`--notchset-check`, `--notchset-control-edge`, `--notchset-draw-from`, `--notchset-ease-bloom`, `--notchset-ease-glide`, `--notchset-ease-key-down`, `--notchset-ease-key-up`, `--notchset-ease-travel`, `--notchset-fade`, `--notchset-focus-color`, `--notchset-focus-inset`, `--notchset-grow-to`, `--notchset-key-down`, `--notchset-key-up`, `--notchset-life-from`, `--notchset-life-ms`, `--notchset-node-blink`, `--notchset-node-bloom`, `--notchset-node-delay`, `--notchset-plate-color`, `--notchset-rise-from`, `--notchset-rule`, `--notchset-scan-to`, `--notchset-scroll`, `--notchset-signal`, `--notchset-sweep-to`, `--notchset-travel`). Never add Tailwind colour classes inside the component.

```tsx
import { DeviceAuth } from "@/components/ui/notchset/blocks/device-auth";
```

## Parts

| Part | data-slot | What it is for |
|---|---|---|
| `DeviceAuth` | `device-auth` | The terminal and the browser's enter, confirm and result steps. |

Style a part with `[data-slot="<slot>"]` selectors or its `className`; keep the attributes when editing.

## Sound
- Keep every `data-slot` and `data-sound` attribute: the sound layer reads them.
- Installing this item adds no audio. Nothing plays until the app mounts `SoundProvider` once (install: `npx shadcn@latest add https://beautiful-ui.dev/r/notchset-sound.json`, import from `@/components/ui/notchset/sound-provider`); `useSound()` gives `muted` and `setMuted` for a mute control. Without a provider the audio engine never loads.

## Match the original
- Read `components/ui/notchset/blocks/device-auth.tsx` as the reference implementation before changing or recreating anything, and match it: sizes, colours per theme, motion timings, copy and behaviour.
- If you deviate (a prop you can't honour, a style you changed, a dependency you swapped), say so in your reply, part by part.
- Keep the accessibility contract, the keyboard map and the motion levels listed below.

## Use it when
- device login, cli login, device authorization, oauth device flow, rfc 8628, connect a device, authorize cli, Notchset
- A CLI, desktop app or TV app that signs in through the browser
- Showing people which scopes a device gets before they approve

### Not when
- Web sign-in: use Sign In
- Service tokens: use API keys

## Mistakes
- Bind the token to the chosen workspace and scopes on the server
- Keep dangerous scopes off by default and show the warning before approval
- Never pre-fill the code from anything but your own deep link (?user_code=)

## Usage

```tsx
import { DeviceAuth } from "@/components/ui/notchset/blocks/device-auth";

export function Device({ code }: { code: string }) {
  return (
    <DeviceAuth
      command="relay login"
      verifyUrl="relay.dev/device"
      userCode={code}
      device={{ name: "relay-cli 2.4 on macOS", facts: [{ label: "DEVICE", value: "Maya's MacBook" }] }}
      workspaces={[{ value: "acme", label: "ACME LABS" }]}
      scopes={[{ id: "runs:read", label: "runs:read", description: "Read runs and traces", defaultOn: true }]}
      onLookup={async (c) => (await fetch(`/api/device/${c}`)).ok}
      onAuthorize={async (grant) => {
        await fetch("/api/device/approve", { method: "POST", body: JSON.stringify(grant) });
        return ["Logged in as maya@acme.dev · Acme Labs"];
      }}
    />
  );
}
```

## Props

| Prop | Type | Default | What it does |
|---|---|---|---|
| `command / verifyUrl / userCode` | `string` |  | What the terminal ran, where to go and the code it shows. |
| `device` | `{ name, facts: { label, value }[] }` |  | What the browser shows on Is this you? |
| `workspaces / scopes` | `options / { id, label, description, defaultOn?, dangerous? }[]` |  | dangerous is the warning shown while it's ticked; such scopes should be off by default. |
| `onLookup / onAuthorize / onDeny` | `(code) => Promise<boolean> / (grant) => Promise<string[]> / () => Promise` |  | Your device-flow endpoints; onAuthorize resolves with the terminal's success lines. |
| `expiresIn / tokenNote / fillLabel` | `number / string / string` |  | Seconds left, the granted note, and a demo-only fill button. |

Full docs: https://beautiful-ui.dev/components/device-auth

## Customising
- Colours: the component reads your shadcn tokens (`--background`, `--foreground`, `--border` …), refined by the `--notchset-*` tokens. The signal colour is `--notchset-signal` (it falls back to `--destructive`). Set tokens on `:root`, or on any container to retheme one area.
- Dark mode follows the `.dark` class on an ancestor (the shadcn and next-themes convention).
- Update later by re-running the install with `--overwrite` (review the diff if you edited it). Changelog: https://beautiful-ui.dev/r/changelog.json

## Keyboard

| Keys | Action |
|---|---|
| Enter | Continue with the code |
| Space | Toggle a scope |
| Tab | Code, workspace, scopes, DENY and AUTHORIZE |

## Performance

- One timer for the clock; nothing else runs while idle.

## Responsive

- The terminal stacks above the browser under 820px (container width).

## Motion inventory

| Interaction | What moves |
|---|---|
| Steps | Each step rises in (300ms) |
| Working | The scanner while waiting, looking up and connecting |
| Approved | The terminal's lines rise in one by one and a fresh caret blinks |
| Expiry | The clock rolls; under a minute it turns signal |

## Accessibility contract (preserve when editing)
- The section is named Device login; the terminal's output is announced (aria-live)
- Scopes are checkboxes (role, aria-checked); the dangerous-scope warning is announced
- The code field marks errors (aria-invalid) tied to its message; the result is a status

## Install

```bash
npx shadcn@latest add @beautiful-ui-pro/device-auth
```

Pro item: needs the `@beautiful-ui-pro` registry in `components.json` and `BEAUTIFUL_UI_TOKEN` in `.env.local` (https://beautiful-ui.dev/account). Setup: https://beautiful-ui.dev/docs/pro. Your components.json `style` picks the build: radix-*, new-york and default get Radix, base-* gets Base UI.

## Credits
- Built on shadcn/ui (https://ui.shadcn.com)

The notchset foundation (the tokens listed above, keyframes and motion levels) installs once with the first component; its CSS is public at https://beautiful-ui.dev/r/notchset-foundation.json.
