The clientId is used to authorize an device. So it should be in the **Authorization** field of the request header.