# fyi.opensocial.access

> Published by [lexicons.opensocial.fyi](https://lexicon.garden/identity/did:plc:2gqnilpksz2e7faj3bwvo6qc)

✓ This is the authoritative definition for this NSID.

## Links

- [View on Lexicon Garden](https://lexicon.garden/lexicon/did:plc:2gqnilpksz2e7faj3bwvo6qc/fyi.opensocial.access)
- [Documentation](https://lexicon.garden/lexicon/did:plc:2gqnilpksz2e7faj3bwvo6qc/fyi.opensocial.access/docs)
- [Examples](https://lexicon.garden/lexicon/did:plc:2gqnilpksz2e7faj3bwvo6qc/fyi.opensocial.access/examples)

## Definitions

### `fyi.opensocial.access`

**Type**: `record`

Who may read this space. Present in every space under the group. The group authority issues space credentials according to this record and nothing else.

**Key**: `literal:self`

| Property | Type | Required | Description |
|----------|------|----------|-------------|
| `createdAt` | `string` (datetime) | Yes |  |
| `credentialScopes` | `array` | No | Which OAuth scopes for the group DID each role may request in this space. |
| `readableBy` | `array` | Yes | Role ids that may read the space, or the literal string 'public' meaning any authenticated requester. |

### `fyi.opensocial.access#roleScopes`

**Type**: `object`

| Property | Type | Required | Description |
|----------|------|----------|-------------|
| `role` | `string` | Yes | A role id: the record key of a fyi.opensocial.role record. |
| `scopes` | `array` | Yes |  |

## Raw Schema

```json
{
  "$type": "com.atproto.lexicon.schema",
  "defs": {
    "main": {
      "description": "Who may read this space. Present in every space under the group. The group authority issues space credentials according to this record and nothing else.",
      "key": "literal:self",
      "record": {
        "properties": {
          "createdAt": {
            "format": "datetime",
            "type": "string"
          },
          "credentialScopes": {
            "description": "Which OAuth scopes for the group DID each role may request in this space.",
            "items": {
              "ref": "#roleScopes",
              "type": "ref"
            },
            "type": "array"
          },
          "readableBy": {
            "description": "Role ids that may read the space, or the literal string 'public' meaning any authenticated requester.",
            "items": {
              "type": "string"
            },
            "type": "array"
          }
        },
        "required": [
          "readableBy",
          "createdAt"
        ],
        "type": "object"
      },
      "type": "record"
    },
    "roleScopes": {
      "properties": {
        "role": {
          "description": "A role id: the record key of a fyi.opensocial.role record.",
          "maxLength": 64,
          "type": "string"
        },
        "scopes": {
          "items": {
            "type": "string"
          },
          "type": "array"
        }
      },
      "required": [
        "role",
        "scopes"
      ],
      "type": "object"
    }
  },
  "id": "fyi.opensocial.access",
  "lexicon": 1
}
```
