fyi.opensocial.getGroupAuth
{
"$type": "com.atproto.lexicon.schema",
"defs": {
"main": {
"description": "Obtain a DPoP-bound OAuth access token to act as the group DID. The host is the group's PDS and authorization server: the caller authenticates with their personal account (service auth) and presents a DPoP proof; the host issues a short-lived token for the group DID whose space: scopes are exactly what the caller's roles are granted by the space's access record. No group password is involved.",
"errors": [
{
"name": "Forbidden"
}
],
"input": {
"encoding": "application/json",
"schema": {
"properties": {
"group": {
"format": "did",
"type": "string"
},
"space": {
"description": "The space the caller intends to write into; its access record's credentialScopes bound the grant.",
"format": "space-ref",
"type": "string"
}
},
"required": [
"group",
"space"
],
"type": "object"
}
},
"output": {
"encoding": "application/json",
"schema": {
"properties": {
"accessJwt": {
"type": "string"
},
"collections": {
"description": "Collections the caller's roles may write as the group in that space ('*' for any).",
"items": {
"type": "string"
},
"type": "array"
},
"did": {
"format": "did",
"type": "string"
},
"expiresAt": {
"format": "datetime",
"type": "string"
},
"pds": {
"description": "Where to use it: the group's PDS (this host).",
"format": "uri",
"type": "string"
},
"repoCollections": {
"description": "Public-repo collections this token may also write.",
"items": {
"type": "string"
},
"type": "array"
},
"scope": {
"description": "The token's OAuth scope string; the PDS enforces it.",
"type": "string"
}
},
"required": [
"did",
"accessJwt",
"pds",
"collections",
"expiresAt"
],
"type": "object"
}
},
"type": "procedure"
}
},
"id": "fyi.opensocial.getGroupAuth",
"lexicon": 1
}
Metadata
- DID
-
did:plc:2gqnilpksz2e7faj3bwvo6qc - CID
-
bafyreiajxco6sode6thptz5g645ya5qbvqfrevt7kgc2apqrgfk2xexjxe - Indexed At
- 2026-09-24 00:10 UTC
- AT-URI
-
at://did:plc:2gqnilpksz2e7faj3bwvo6qc/com.atproto.lexicon.schema/fyi.opensocial.getGroupAuth
Similar Lexicons
Lexicons whose schemas describe something close to this one. Check them before publishing a new one that overlaps.
-
fyi.opensocial.provisionGroup procedure
Host-level: an app creates a group for a person and gets its own OAuth session on it. Authenticated twice: the person asking, by service auth from their PDS (they become the founder), and the app, by OAuth client authen…
-
Hands the AppView access to one of the requesting user's personal spaces. The client mints a delegation token on its own PDS for the space and passes it here, because a delegation token is single-use and short-lived and…
-
fyi.opensocial.access record
Who may read this space. Present in every space under the group. The group authority issues space credentials according to this record and nothing else.
-
An app's pending request to sign in as a group, as the caller would approve it: the app, the groups the caller may act for, and for each one what the caller's roles let the app do. Called by the console's approval page,…