OpenAPI 3.2 adds deviceAuthorization to the OAuth Flows Object. A description records the device authorization URL, token URL, and available scopes. In the underlying OAuth flow, a device displays a code, the user approves on another screen, and the device waits for a token.
The demo plays through code display, approval on another screen, and token issuance. An OpenAPI description does not implement the authorization server; polling, expiry, scopes, and errors must follow the OAuth device flow and actual server behavior.
When to use
Use it when documenting API authorization for TVs or CLIs with limited input or browser access.