Skip to content →
Log in

Authorize a device

Bind a new endpoint to your user and organization.

Interactive browser authorization is the standard enrollment flow.

Authorize#

  1. Start login: run pulsectl login on Linux, or choose Continue in Browser in the macOS PulseHA app.
  2. Open the displayed browser page.
  3. Sign in through the organization’s configured authentication method.
  4. Enter or confirm the device code and approve the endpoint.
  5. Return to Network → Devices and wait for the device to leave Pending.

The device is associated with the approving user. Required SSO applies to the browser session.

Troubleshooting#

Expired codes must be restarted from the agent. A Blocked or Archived device must be restored by an authorized operator. Revocation is irreversible; enroll the endpoint again.

Enrollment tokens and workload identity are API-managed options, not Console-generated replacements for this flow.