Devices · 8 min

Sign in on a TV or a terminal

Some devices cannot show you a sign-in form, so they show a short code instead. By the end of this guide you will know how to approve that code from your phone, how to refuse one you did not ask for, and what to do when a code stops working.

What the device shows you

A television, a set-top box or a terminal window has no comfortable way to take an email address and a password. So it asks us for a short code, prints it on its own screen, and waits. You do the signing in somewhere easier, and the device is let in afterwards.

The code is eight characters in two groups of four, like KRPD-7T4M. Next to it the device shows the address to open, which is cybercorp.ai/device. Some devices print that address with the code already attached, and a terminal running on your own computer may open the page for you.

The device shows you two things and waits. Everything you do, you do somewhere else.cybercorp.ai/deviceKRPD-7T4MThe address to open in a browserThe code, in two groups of fourYou type nothing on the device
The device shows you two things and waits. Everything you do, you do somewhere else.
Code
Eight characters, in two groups of four
Characters
Capital letters and digits only
Never appears
The digit zero, the digit one, the letter O, the letter I
Lasts
Ten minutes from the moment the device asks for it
Uses
One. Approving or refusing finishes it
Approved at
cybercorp.ai/device, in a browser where you are signed in

How the three parts fit together

Three parties are involved, and it helps to know which one is doing what. The device asks us for a code. You read that code off the screen and approve it from a browser. We then hand the device its way in, and it finishes signing in on its own.

You never type a password into the device. It only ever learns that somebody with an account said yes.The deviceA TV or a terminalYouA phone or a computerCyber CorpThe serviceAsks for a codeWe send back a codeShows the code on its screenWhile it waits, the device asks us again every five seconds.You type the code and approveThe device is let in
You never type a password into the device. It only ever learns that somebody with an account said yes.

That last part is why the device seems to know the moment you press the button. It is not being told; it is asking, quietly, every five seconds, until it gets an answer.

Approve it from your phone or computer

  1. Open the approval page

    In a browser on your phone or computer, go to cybercorp.ai/device. If the device printed a link with the code in it, that link takes you to the same page with the box already filled in.

  2. Sign in if the page asks you to

    You have to be signed in to approve anything. If you are not, the page says so and offers a link straight back to this page, so you land here again with the code still in the box.

  3. Type the code

    Capitals or lower case both work, and the dash is optional. The box tidies the code as you type. Nothing is sent until all eight characters are there.

  4. Read what is asking

    As soon as the code is complete, a panel appears naming the device, the address the request came from, and the account it would reach. This is the part worth slowing down for.

  5. Choose Authorize the device

    The page confirms authorization. The device then finishes signing in by polling for the result. You can close the approval tab once authorization is confirmed.

cybercorp.ai/device
Device codeKRPD-7T4M
This request comes fromCyberCorpTV/2.4 (Android TV)
Address82.64.118.7
It will get access toyou@example.com
Code lifetime10 minutes from creation
Authorize the deviceLets it in
I did not start this — refuseShuts it out
The panel that appears once the whole code is in the box. If any line surprises you, refuse instead.

The device line shows the user-agent supplied by the requesting app; it can be a technical string, not the name you gave your television. The address is where the request reached us from. Check that both match the device and network you are setting up.

If you did not start this

The trick works because the screen looks reassuring: it is our page, on our address, and you are properly signed in. Everything is genuine except the one thing that matters, which is whose device is on the other end. Nobody at Cyber Corp will ever send you a code or ask you to read one out.

When a code arrives unasked, the safest thing is to do nothing at all: close the page, and the code dies on its own within ten minutes. If you want to close it now, type the code and choose I did not start this — refuse, underneath the button. The device is told it was turned down and gets nothing. Refusing records no link between that device and your account.

Every code has exactly one ending. Once it has ended, the device has to ask for a new one.Code createdPending for ten minutesYou approveYou refuseTen minutes passThe device is signed inThe device is given nothingThe code expires by itself
Every code has exactly one ending. Once it has ended, the device has to ask for a new one.

When the code will not work

Most failures here are one of five things, and none of them do any harm. The page names the first four the moment you try. The fifth one shows itself on the device, which keeps waiting even though you have already approved it.

What the page says, and what to do about it
What you seeWhat it meansWhat to do
That code is not valid. Check it and try again.Those eight characters do not match any code we are holding. Almost always a misread character.Read the code off the device again. No code contains a zero, a one, the letter O or the letter I.
That code has expired. Start again from your device.More than ten minutes passed between the device asking and you approving.Ask the device for a fresh code, then start again from the top.
That code has already been used.It was approved or refused once already. Each code works a single time either way.Ask the device for a fresh code.
You must be signed inThe browser you opened the page in has no session on it.Use the sign-in link on the page, then come back. Your code is carried across for you.
You approved it, but the device never signs inThe account itself has never been activated, so it cannot sign in anywhere at all.Open the activation link in the email sent when the account was created, then pair the device again.

An activation link lasts twenty-four hours and works once. If yours has gone stale, go to the sign-in page and try to sign in with the same details: a Resend email link appears beside the Username / Email label. Open the new link, then pair the device again.

Signing a device out later

If the device is still in front of you, the simplest answer is to sign out on the device itself. That ends its session and no other, and nothing else on your account is disturbed.

Settings → My Account does not currently list paired devices or offer individual remote sign-out. If you no longer have the device, change or reset your password to revoke all its refresh sessions, then sign in again on the devices you keep.

To change your password, open Settings → My Account and choose Change on the Password row. Changing or resetting it revokes every refresh session. A device may retain valid access for up to 15 minutes, then must sign in again.

Available sign-out options
What you doWhere you do itWhat it signs out
Sign out on the deviceOn the device itself, if it is still in front of you.That session and no other. Nothing else on your account is disturbed.
Reset a forgotten password/forget_password, with access to your inbox.Revokes all refresh sessions after the new password is saved.
Change your passwordSettings, then My Account, the Password row. A reset from the sign-in page does the same.Revokes every refresh session; existing valid access may last up to 15 minutes.

Read next