Devices
This device as a client of the account on the relay: enroll, approve, rename, revoke and the audit log.
This device as a client of the account on the relay: enroll, approve, rename, revoke and the audit log.
auth.devices(relay_url, name) returns this device on the relay, its key in the session's credential store (shared with the cua CLI and daemon). A device lists and reaches the account's machines once enrolled: right after a fresh sign-in (a sign-in through Auth.begin_login re-registers a device that already has a key), or by a one-time code approved from an enrolled device (cua devices approve). A new key of the same machine replaces its old record. Enrollment lasts 30 days, then one approval or a fresh sign-in re-verifies it. Nothing here prompts; gate approve behind presence in your UI.
Devices#This device as a client of the signed-in account on a relay: its
enrollment, the account's other devices and its audit log. The device
key lives in the session's vault (shared with the cua CLI and daemon).
Nothing here prompts: approving is the caller's to gate behind presence.
Returned by Auth.devices.
| Method | Description |
|---|---|
approve | Approves the device showing code, or re-verifies device_id, from this enrolled device. |
check_enrolled | Whether the relay lets this device open a session now (enrolled), asked afresh. |
confirm_machine | Vouches for machine_id, a machine that registered without an enrolled device's signature or MFA (from this enrolled device) (S5). |
device_id | This device's id, when it has a key (no network). |
enroll | Registers this device (creating its key on first use). |
rename | Renames a device (from this enrolled device). |
revoke | Revokes a device (from this enrolled device). |
snapshot | The account's devices, the grace period, the newest audit_limit audit events and the machines' names. |
| Accessor | Returns | Description |
|---|---|---|
relay_url() | String | The relay base URL. |
Devices.approve#Approves the device showing code, or re-verifies device_id,
from this enrolled device.
async def approve(self, code: Optional[str], device_id: Optional[str]) -> RelayDevice| Parameter | Type | Default |
|---|---|---|
code | Option<String> | required |
device_id | Option<String> | required |
Returns RelayDevice · Async · Raises CuaError
Devices.check_enrolled#Whether the relay lets this device open a session now (enrolled), asked afresh. Polled while waiting for an approval.
async def check_enrolled(self) -> boolReturns bool · Async
Devices.confirm_machine#Vouches for machine_id, a machine that registered without an
enrolled device's signature or MFA (from this enrolled device) (S5).
Clears RelayMachine.confirmed's "new" flag for every account
member, not just this device.
async def confirm_machine(self, machine_id: str) -> RelayMachine| Parameter | Type | Default |
|---|---|---|
machine_id | String | required |
Returns RelayMachine · Async · Raises CuaError
Devices.device_id#This device's id, when it has a key (no network).
def device_id(self) -> Optional[str]Returns Option<String> · Raises CuaError
Devices.enroll#Registers this device (creating its key on first use). Right after a fresh sign-in it is enrolled at once (replacing this machine's older device key, if any); otherwise the result carries a one-time code to approve from an enrolled device.
async def enroll(self) -> DeviceEnrollmentReturns DeviceEnrollment · Async · Raises CuaError
Devices.rename#Renames a device (from this enrolled device).
async def rename(self, id: str, name: str) -> RelayDevice| Parameter | Type | Default |
|---|---|---|
id | String | required |
name | String | required |
Returns RelayDevice · Async · Raises CuaError
Devices.revoke#Revokes a device (from this enrolled device). Revoking this device also deletes its key.
async def revoke(self, id: str) -> RelayDevice| Parameter | Type | Default |
|---|---|---|
id | String | required |
Returns RelayDevice · Async · Raises CuaError
Devices.snapshot#The account's devices, the grace period, the newest audit_limit
audit events and the machines' names. Only the device list must
succeed; the rest is empty when the relay refuses it.
async def snapshot(self, audit_limit: int) -> DevicesSnapshot| Parameter | Type | Default |
|---|---|---|
audit_limit | u32 | required |
Returns DevicesSnapshot · Async · Raises CuaError
DevicesSnapshot record#Everything the Devices page reads, in one call.
Returned by Devices.snapshot.
| Field | Type | Default | Description |
|---|---|---|---|
local_device_id / localDeviceId | Option<String> | This device's id, when it has a key. | |
devices | Vec<RelayDevice> | The account's devices (this one marked current once enrolled). | |
enforce_after / enforceAfter | Option<u64> | End of the relay's grace period for unenrolled devices. | |
audit | Vec<RelayAuditEvent> | The account's audit log, newest last (empty when the relay refuses). | |
machine_names / machineNames | HashMap<String, String> | Machine ids to names (empty when this device cannot list them). | |
machines | Vec<RelayMachine> | The account's relay machines, RelayMachine.confirmed included (S5; empty when this device cannot list them, same as machine_names). |
RelayDevice record#A client device of the account, as the relay lists it.
Returned by Devices.approve, Devices.rename, Devices.revoke.
| Field | Type | Default | Description |
|---|---|---|---|
id | String | dev_…. | |
name | String | Display name. | |
state | String | pending, enrolled, expired or revoked. | |
platform | String | Operating system it reported (macos, windows, linux); empty when unknown. | |
created_at / createdAt | u64 | Registered at (Unix seconds). | |
enrolled_until / enrolledUntil | Option<u64> | Re-verification due at (Unix seconds). | |
last_seen / lastSeen | Option<u64> | Last session (Unix seconds). | |
current | bool | This device. |
RelayAuditEvent record#One event of the account's audit log.
| Field | Type | Default | Description |
|---|---|---|---|
ts | u64 | Unix seconds. | |
kind | String | Kind (machine_access, device_enrolled, share_added, ...). | |
device | Option<String> | Acting device. | |
machine | Option<String> | Machine id. | |
subject | Option<String> | Other party. | |
detail | Option<String> | Detail. |
DeviceEnrollment record#Devices.enroll's result.
Returned by Devices.enroll.
| Field | Type | Default | Description |
|---|---|---|---|
device | RelayDevice | This device. | |
enrolled | bool | Enrolled now (right after a fresh sign-in). | |
code | Option<String> | The one-time code to approve from an enrolled device otherwise. |