pair_exchange
POST
/v1/pair/exchange
const url = 'https://example.com/v1/pair/exchange';const options = { method: 'POST', headers: {'Content-Type': 'application/json'}, body: '{"code":"example","name":"example","cookie":true}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://example.com/v1/pair/exchange \ --header 'Content-Type: application/json' \ --data '{ "code": "example", "name": "example", "cookie": true }'Remote listener only. Trades a one-time pairing code for a device token. Rate-limited per peer IP; every attempt counts.
Request Bodyrequired
Section titled “Request Bodyrequired”Media typeapplication/json
object
code
required
string
name
string | null
cookie
Browser flow: set HttpOnly session cookies instead of returning the token.
boolean
Examplegenerated
{ "code": "example", "name": "example", "cookie": true}Responses
Section titled “Responses”Media typeapplication/json
object
device
required
A paired remote device. The bearer token itself is never stored; only its
SHA-256 digest is (see remote::hash_token).
object
id
required
string
name
required
string
scope
required
view (read-only) or decide (adds decision, cancel and test requests).
string
enabled
required
boolean
push
required
boolean
created_at
required
integer format: int64
last_seen
integer | null format: int64
token
Long-lived device token (hu_ + 64 hex). Omitted in the cookie flow.
string | null
host
This computer’s name (its hostname), so a device paired with several computers can tell them apart. Absent when unknown.
string | null
Examplegenerated
{ "device": { "id": "example", "name": "example", "scope": "example", "enabled": true, "push": true, "created_at": 1, "last_seen": 1 }, "token": "example", "host": "example"}Invalid, used, or expired code
Rate limited