# fyi.opensocial.getAuthorization

> Published by [lexicons.opensocial.fyi](https://lexicon.garden/identity/did:plc:2gqnilpksz2e7faj3bwvo6qc)

✓ This is the authoritative definition for this NSID.

## Links

- [View on Lexicon Garden](https://lexicon.garden/lexicon/did:plc:2gqnilpksz2e7faj3bwvo6qc/fyi.opensocial.getAuthorization)
- [Documentation](https://lexicon.garden/lexicon/did:plc:2gqnilpksz2e7faj3bwvo6qc/fyi.opensocial.getAuthorization/docs)
- [Examples](https://lexicon.garden/lexicon/did:plc:2gqnilpksz2e7faj3bwvo6qc/fyi.opensocial.getAuthorization/examples)

## Definitions

### `fyi.opensocial.getAuthorization#client`

**Type**: `object`

| Property | Type | Required | Description |
|----------|------|----------|-------------|
| `id` | `string` | Yes |  |
| `logo` | `string` (uri) | No |  |
| `name` | `string` | No |  |
| `uri` | `string` (uri) | No |  |

### `fyi.opensocial.getAuthorization#group`

**Type**: `object`

| Property | Type | Required | Description |
|----------|------|----------|-------------|
| `avatar` | `string` (uri) | No |  |
| `did` | `string` (did) | Yes |  |
| `displayName` | `string` | No |  |
| `granted` | `array` | Yes | The requested scope values the caller's roles let the app have. |
| `handle` | `string` | Yes |  |
| `roles` | `array` | Yes |  |
| `withheld` | `array` | Yes | The requested scope values the app will not get. |

### `fyi.opensocial.getAuthorization#label`

**Type**: `object`

| Property | Type | Required | Description |
|----------|------|----------|-------------|
| `scope` | `string` | Yes |  |
| `text` | `string` | Yes |  |

### `fyi.opensocial.getAuthorization`

**Type**: `query`

An app's pending request to sign in as a group, as the caller would approve it: the app, the groups the caller may act for, and for each one what the caller's roles let the app do. Called by the console's approval page, with service auth from the caller's own PDS.

#### Parameters

| Property | Type | Required | Description |
|----------|------|----------|-------------|
| `requestUri` | `string` | Yes | The request_uri the app received from this host's pushed authorization request endpoint. |

#### Output

**Encoding**: `application/json`

| Property | Type | Required | Description |
|----------|------|----------|-------------|
| `client` | `ref` → `#client` | Yes |  |
| `groups` | `array` | Yes | The groups the caller may sign in as: the one the app named, or every group on this host where the caller holds a role. |
| `labels` | `array` | No | What each permission set the app asked for says it is for, in its own words. |
| `loginHint` | `string` | No | The group the app named, if it named one. |
| `requested` | `array` | Yes | The scope values the app asked for. |

#### Errors

- **ExpiredRequest**

## Raw Schema

```json
{
  "$type": "com.atproto.lexicon.schema",
  "defs": {
    "client": {
      "properties": {
        "id": {
          "type": "string"
        },
        "logo": {
          "format": "uri",
          "type": "string"
        },
        "name": {
          "type": "string"
        },
        "uri": {
          "format": "uri",
          "type": "string"
        }
      },
      "required": [
        "id"
      ],
      "type": "object"
    },
    "group": {
      "properties": {
        "avatar": {
          "format": "uri",
          "type": "string"
        },
        "did": {
          "format": "did",
          "type": "string"
        },
        "displayName": {
          "type": "string"
        },
        "granted": {
          "description": "The requested scope values the caller's roles let the app have.",
          "items": {
            "type": "string"
          },
          "type": "array"
        },
        "handle": {
          "type": "string"
        },
        "roles": {
          "items": {
            "type": "string"
          },
          "type": "array"
        },
        "withheld": {
          "description": "The requested scope values the app will not get.",
          "items": {
            "type": "string"
          },
          "type": "array"
        }
      },
      "required": [
        "did",
        "handle",
        "roles",
        "granted",
        "withheld"
      ],
      "type": "object"
    },
    "label": {
      "properties": {
        "scope": {
          "type": "string"
        },
        "text": {
          "type": "string"
        }
      },
      "required": [
        "scope",
        "text"
      ],
      "type": "object"
    },
    "main": {
      "description": "An app's pending request to sign in as a group, as the caller would approve it: the app, the groups the caller may act for, and for each one what the caller's roles let the app do. Called by the console's approval page, with service auth from the caller's own PDS.",
      "errors": [
        {
          "name": "ExpiredRequest"
        }
      ],
      "output": {
        "encoding": "application/json",
        "schema": {
          "properties": {
            "client": {
              "ref": "#client",
              "type": "ref"
            },
            "groups": {
              "description": "The groups the caller may sign in as: the one the app named, or every group on this host where the caller holds a role.",
              "items": {
                "ref": "#group",
                "type": "ref"
              },
              "type": "array"
            },
            "labels": {
              "description": "What each permission set the app asked for says it is for, in its own words.",
              "items": {
                "ref": "#label",
                "type": "ref"
              },
              "type": "array"
            },
            "loginHint": {
              "description": "The group the app named, if it named one.",
              "type": "string"
            },
            "requested": {
              "description": "The scope values the app asked for.",
              "items": {
                "type": "string"
              },
              "type": "array"
            }
          },
          "required": [
            "client",
            "groups",
            "requested"
          ],
          "type": "object"
        }
      },
      "parameters": {
        "properties": {
          "requestUri": {
            "description": "The request_uri the app received from this host's pushed authorization request endpoint.",
            "type": "string"
          }
        },
        "required": [
          "requestUri"
        ],
        "type": "params"
      },
      "type": "query"
    }
  },
  "id": "fyi.opensocial.getAuthorization",
  "lexicon": 1
}
```
