Home › Guide › How codes work
How TV sign-in codes work
A television has no keyboard worth using, so the sign-in happens somewhere else. The screen shows a short code next to a short address, then waits. Everything that follows is a conversation between the TV and the service — the phone only ever speaks to the service.
Every plate in this guide — a Roku printing roku.com/link, a Netflix screen showing eight slots, a YouTube app pointing at yt.be/activate — is the same mechanism wearing a different coat. It has a name: the device authorization grant, published as an internet standard (RFC 8628) in August 2019 after years of use by Google, Microsoft and others. Knowing the mechanism makes every screen legible.
The idea is simple. A device that cannot comfortably take a password asks the service for a pair of codes. One of them, the user code, is printed on the screen with a short address. The other, the device code, is kept by the device and never shown; the standard says outright that it should not be displayed. The viewer takes the printed code to a phone or computer, opens the address, signs in to the account, and types the code. Meanwhile the device keeps asking the service, every few seconds, whether the viewer has finished. When the answer is yes, the screen changes.
Two devices, one sign-in
The reason the phone never needs to find the TV is that both of them talk to the same service. The TV is holding a device code that identifies its request. The phone hands the service a user code that identifies the same request from the other side. The service matches the two, checks that the account on the phone has agreed, and then releases the TV. Nothing passes over the home network between the two screens, which is why the sign-in works equally well from a phone on mobile data or a computer in another building.
It also explains a detail that surprises people: the TV does not know when the code has been typed. It only finds out because it asks. The standard describes the TV asking at an interval the service sets — five seconds if the service says nothing — and receiving one of a small set of answers: still pending, slow down, expired, refused, or granted. Disney+’s own documentation describes the visible result of granted: the TV screen refreshes by itself with a successful activation prompt.
Why the address is short
The standard asks services to make the printed address short and easy to remember, because it expects a person to type it by hand from across a room. That is the whole reason such addresses exist: roku.com/link, yt.be/activate, netflix.com/tv2 and link.apple.com are memorable because they have to be.
A short address is a doorway, not the room. Typed into a browser, roku.com/link opens my.roku.com/link; yt.be/activate opens a page on accounts.google.com; HBOMax.com/signin opens auth.hbomax.com. Each jump lands on a different-looking name that belongs to the same company — its account or sign-in host — and the part of the address that identifies the owner (roku.com, google.com, hbomax.com) is unchanged. The guide page on reading the address takes this apart in detail.
The shape of the code
The standard is specific about what a good user code looks like, because it has to survive being read off a screen and typed on a phone. It recommends letters over digits, in upper case, with the confusable pairs removed — no zero and letter O, no one and letter I — and offers a twenty-letter consonant alphabet as one way to do it. Its worked examples are WDJB-MJHT, eight letters in two groups, and 019-450-730, nine digits in three. Services choose differently: Disney+ prints eight digits, HBO Max six, Google two groups of four letters, Plex four characters. The explorer below shows each shape as it appears on a screen.
| Service | Printed address | Shape | Source of the shape |
|---|---|---|---|
| Disney+ | DisneyPlus.com/begin | 8 digits | Stated by Disney+ |
| HBO Max | HBOMax.com/signin | 6 digits | Stated by HBO Max |
| Netflix | netflix.com/tv2 | 8 characters, two groups of four | The page’s eight slots, read live |
| YouTube | yt.be/activate | Two groups of four letters | Google’s developer documentation |
| Plex | plex.tv/link | 4 characters | Stated by Plex |
| Xfinity Stream | xfinity.com/authorize | 6 digits | Stated by Xfinity |
| Roku, Amazon, Apple, Hulu, Peacock, Paramount+ | see each plate | A short block of letters and digits | Length not published |
How long a code lives
Every code pair is issued with a lifetime, and the printed code dies with it. Google’s documentation shows an example lifetime of thirty minutes; Microsoft’s says fifteen by default. Peacock’s page puts it from the viewer’s side: a code that is not accepted may simply have expired, and the app prints a fresh one. Nothing revives an expired code and nothing needs to — the next one is free and immediate.
The other clock runs after the code is accepted. Hulu’s page puts the wait at about half a minute; in practice the delay is whatever remains of the TV’s polling interval, because the TV learns the news only when it next asks.
The square code and the pre-filled page
Most screens now show a square code beside the typed address. The standard anticipated this too: alongside the bare verification address it defines a second one with the user code already embedded, meant to be carried by a QR code or a short link so that the viewer types nothing at all. Netflix’s page makes the pair visible in one sentence — confirm or enter the code: confirm if the square was scanned and the code came with it, enter if the address was typed. YouTube’s documentation offers the same choice in the same breath: scan the QR code, or go to yt.be/activate.
A scanned square code opens a page on the service’s own domain, exactly as the typed address does. The camera reads an address; it does not read a code into the TV.
Codes that travel the other way
Not every code on a TV is a user code waiting to be typed elsewhere. Google’s setup for Android TV generates a code on the phone and asks for it on the TV; Google TV setup scans a square on the TV with the Google Home app. Roku and Netflix both offer a route with no code at all, in which an e-mail address typed on the TV brings a sign-in link to the viewer’s inbox and opening that link signs the TV in. The plates in this guide note which routes each service describes.
What the standard says about impostors
The standard’s security section describes a risk it calls remote phishing: someone starts the code sign-in on a device they hold, obtains the user code, and persuades another person to enter that code on their own account. If the trick works, the stranger’s device is now signed in to the victim’s account. The standard’s answer is for the sign-in page to say clearly that a device is being connected — which is why Google’s page is headed Connect a device and shows a consent screen naming the app before it agrees.
Roku’s own warning describes the same pattern from the other direction: an impostor links a viewer’s device to the impostor’s account, and then charges to release it. Both stories end in the same rule. A code is entered only when it came from a screen the viewer is looking at, on the address that screen printed, and never on anyone else’s instruction.