fyi.opensocial.getGroupAuth

lexicons.opensocial.fyi

{
  "$type": "com.atproto.lexicon.schema",
  "defs": {
    "main": {
      "description": "Obtain a DPoP-bound OAuth access token to act as the group DID. The host is the group's PDS and authorization server: the caller authenticates with their personal account (service auth) and presents a DPoP proof; the host issues a short-lived token for the group DID whose space: scopes are exactly what the caller's roles are granted by the space's access record. No group password is involved.",
      "errors": [
        {
          "name": "Forbidden"
        }
      ],
      "input": {
        "encoding": "application/json",
        "schema": {
          "properties": {
            "group": {
              "format": "did",
              "type": "string"
            },
            "space": {
              "description": "The space the caller intends to write into; its access record's credentialScopes bound the grant.",
              "format": "space-ref",
              "type": "string"
            }
          },
          "required": [
            "group",
            "space"
          ],
          "type": "object"
        }
      },
      "output": {
        "encoding": "application/json",
        "schema": {
          "properties": {
            "accessJwt": {
              "type": "string"
            },
            "collections": {
              "description": "Collections the caller's roles may write as the group in that space ('*' for any).",
              "items": {
                "type": "string"
              },
              "type": "array"
            },
            "did": {
              "format": "did",
              "type": "string"
            },
            "expiresAt": {
              "format": "datetime",
              "type": "string"
            },
            "pds": {
              "description": "Where to use it: the group's PDS (this host).",
              "format": "uri",
              "type": "string"
            },
            "repoCollections": {
              "description": "Public-repo collections this token may also write.",
              "items": {
                "type": "string"
              },
              "type": "array"
            },
            "scope": {
              "description": "The token's OAuth scope string; the PDS enforces it.",
              "type": "string"
            }
          },
          "required": [
            "did",
            "accessJwt",
            "pds",
            "collections",
            "expiresAt"
          ],
          "type": "object"
        }
      },
      "type": "procedure"
    }
  },
  "id": "fyi.opensocial.getGroupAuth",
  "lexicon": 1
}

Validate Record

Validate a record against fyi.opensocial.getGroupAuth

Validation Options
Treat any remaining unresolved references as valid

Metadata

DID
did:plc:2gqnilpksz2e7faj3bwvo6qc
CID
bafyreiajxco6sode6thptz5g645ya5qbvqfrevt7kgc2apqrgfk2xexjxe
Indexed At
2026-09-24 00:10 UTC
AT-URI
at://did:plc:2gqnilpksz2e7faj3bwvo6qc/com.atproto.lexicon.schema/fyi.opensocial.getGroupAuth

Similar Lexicons

Lexicons whose schemas describe something close to this one. Check them before publishing a new one that overlaps.

  • Host-level: an app creates a group for a person and gets its own OAuth session on it. Authenticated twice: the person asking, by service auth from their PDS (they become the founder), and the app, by OAuth client authen…

  • Hands the AppView access to one of the requesting user's personal spaces. The client mints a delegation token on its own PDS for the space and passes it here, because a delegation token is single-use and short-lived and…

  • Who may read this space. Present in every space under the group. The group authority issues space credentials according to this record and nothing else.

  • An app's pending request to sign in as a group, as the caller would approve it: the app, the groups the caller may act for, and for each one what the caller's roles let the app do. Called by the console's approval page,…

Lexicon Garden

@