Obtain a DPoP-bound OAuth access token to act as the group DID. The host is the group's PDS and authorization server: the caller authenticates with their personal account (service auth) and presents a DPoP proof; the host issues a short-lived token for the group DID whose space: scopes are exactly what the caller's roles are granted by the space's access record. No group password is involved.
Input
application/jsongroup
stringdid
Required
A decentralized identifier (DID).
space
stringspace-ref
Required
The space the caller intends to write into; its access record's credentialScopes bound the grant.
Output
application/jsonaccessJwt
string
Required
No description available.
collections
array
Required
Collections the caller's roles may write as the group in that space ('*' for any).
did
stringdid
Required
A decentralized identifier (DID).
expiresAt
stringdatetime
Required
An RFC 3339 formatted timestamp.
pds
stringuri
Required
Where to use it: the group's PDS (this host).
repoCollections
array
Optional
Public-repo collections this token may also write.
scope
string
Optional
The token's OAuth scope string; the PDS enforces it.
Errors
Forbidden
Try It
Requests are sent directly from your browser. Some servers may block requests due to CORS.
View raw schema
{
"description": "Obtain a DPoP-bound OAuth access token to act as the group DID. The host is the group's PDS and authorization server: the caller authenticates with their personal account (service auth) and presents a DPoP proof; the host issues a short-lived token for the group DID whose space: scopes are exactly what the caller's roles are granted by the space's access record. No group password is involved.",
"errors": [
{
"name": "Forbidden"
}
],
"input": {
"encoding": "application/json",
"schema": {
"properties": {
"group": {
"format": "did",
"type": "string"
},
"space": {
"description": "The space the caller intends to write into; its access record's credentialScopes bound the grant.",
"format": "space-ref",
"type": "string"
}
},
"required": [
"group",
"space"
],
"type": "object"
}
},
"output": {
"encoding": "application/json",
"schema": {
"properties": {
"accessJwt": {
"type": "string"
},
"collections": {
"description": "Collections the caller's roles may write as the group in that space ('*' for any).",
"items": {
"type": "string"
},
"type": "array"
},
"did": {
"format": "did",
"type": "string"
},
"expiresAt": {
"format": "datetime",
"type": "string"
},
"pds": {
"description": "Where to use it: the group's PDS (this host).",
"format": "uri",
"type": "string"
},
"repoCollections": {
"description": "Public-repo collections this token may also write.",
"items": {
"type": "string"
},
"type": "array"
},
"scope": {
"description": "The token's OAuth scope string; the PDS enforces it.",
"type": "string"
}
},
"required": [
"did",
"accessJwt",
"pds",
"collections",
"expiresAt"
],
"type": "object"
}
},
"type": "procedure"
}