fyi.opensocial.getAuthorization

lexicons.opensocial.fyi

{
  "$type": "com.atproto.lexicon.schema",
  "defs": {
    "client": {
      "properties": {
        "id": {
          "type": "string"
        },
        "logo": {
          "format": "uri",
          "type": "string"
        },
        "name": {
          "type": "string"
        },
        "uri": {
          "format": "uri",
          "type": "string"
        }
      },
      "required": [
        "id"
      ],
      "type": "object"
    },
    "group": {
      "properties": {
        "avatar": {
          "format": "uri",
          "type": "string"
        },
        "did": {
          "format": "did",
          "type": "string"
        },
        "displayName": {
          "type": "string"
        },
        "granted": {
          "description": "The requested scope values the caller's roles let the app have.",
          "items": {
            "type": "string"
          },
          "type": "array"
        },
        "handle": {
          "type": "string"
        },
        "roles": {
          "items": {
            "type": "string"
          },
          "type": "array"
        },
        "withheld": {
          "description": "The requested scope values the app will not get.",
          "items": {
            "type": "string"
          },
          "type": "array"
        }
      },
      "required": [
        "did",
        "handle",
        "roles",
        "granted",
        "withheld"
      ],
      "type": "object"
    },
    "label": {
      "properties": {
        "scope": {
          "type": "string"
        },
        "text": {
          "type": "string"
        }
      },
      "required": [
        "scope",
        "text"
      ],
      "type": "object"
    },
    "main": {
      "description": "An app's pending request to sign in as a group, as the caller would approve it: the app, the groups the caller may act for, and for each one what the caller's roles let the app do. Called by the console's approval page, with service auth from the caller's own PDS.",
      "errors": [
        {
          "name": "ExpiredRequest"
        }
      ],
      "output": {
        "encoding": "application/json",
        "schema": {
          "properties": {
            "client": {
              "ref": "#client",
              "type": "ref"
            },
            "groups": {
              "description": "The groups the caller may sign in as: the one the app named, or every group on this host where the caller holds a role.",
              "items": {
                "ref": "#group",
                "type": "ref"
              },
              "type": "array"
            },
            "labels": {
              "description": "What each permission set the app asked for says it is for, in its own words.",
              "items": {
                "ref": "#label",
                "type": "ref"
              },
              "type": "array"
            },
            "loginHint": {
              "description": "The group the app named, if it named one.",
              "type": "string"
            },
            "requested": {
              "description": "The scope values the app asked for.",
              "items": {
                "type": "string"
              },
              "type": "array"
            }
          },
          "required": [
            "client",
            "groups",
            "requested"
          ],
          "type": "object"
        }
      },
      "parameters": {
        "properties": {
          "requestUri": {
            "description": "The request_uri the app received from this host's pushed authorization request endpoint.",
            "type": "string"
          }
        },
        "required": [
          "requestUri"
        ],
        "type": "params"
      },
      "type": "query"
    }
  },
  "id": "fyi.opensocial.getAuthorization",
  "lexicon": 1
}

Validate Record

Validate a record against fyi.opensocial.getAuthorization

Validation Options
Treat any remaining unresolved references as valid

Metadata

DID
did:plc:2gqnilpksz2e7faj3bwvo6qc
CID
bafyreia4rb3swb3gkg4siqxvuou2oujcdsdswcw7wxze5wrzytanszwyqe
Indexed At
2026-10-02 21:53 UTC
AT-URI
at://did:plc:2gqnilpksz2e7faj3bwvo6qc/com.atproto.lexicon.schema/fyi.opensocial.getAuthorization

Similar Lexicons

Lexicons whose schemas describe something close to this one. Check them before publishing a new one that overlaps.

  • Approve an app's pending request to sign in as a group. The app gets what the caller's roles in the group allow and nothing more, and every token it obtains is recorded as the caller's. Returns the URL to send the brows…

  • Obtain a DPoP-bound OAuth access token to act as the group DID. The host is the group's PDS and authorization server: the caller authenticates with their personal account (service auth) and presents a DPoP proof; the ho…

Lexicon Garden

@