website/docs/endpoint-devices/authentik-agent/configuration.md
Before deploying the authentik Agent, configure your authentik deployment. This involves:
The OAuth device code flow enables secure authentication for input-limited clients like CLI tools and is required for the authentik Agent to function.
If you have already deployed the authentik OAuth device code flow, skip to the next section.
default-device-code-flow)Device code flow)default-device-code-flow)Stage ConfigurationRequire authenticationThe authentik agent requires an OAuth application/provider pair to handle authentication.
Log in to authentik as an administrator and open the authentik Admin interface.
Navigate to Applications > Applications and click Create with Provider to create an application and provider pair. (Alternatively you can first create a provider separately, then create the application and connect it with the provider.)
authentik-cli, and provide an optional group for the type of application, the policy engine mode, and optional UI settings.Public.authentik-cli.authentik default OAuth Mapping: OpenID 'offline_access' scope.Click Submit to save the new application and provider.
The authentik Agent Connector allows device information to be reported to authentik.
authentik Agent)authentik-cli provider that you created in the previous section.