# fyi.opensocial.getGroupAuth

> Published by [lexicons.opensocial.fyi](https://lexicon.garden/identity/did:plc:2gqnilpksz2e7faj3bwvo6qc)

✓ This is the authoritative definition for this NSID.

## Links

- [View on Lexicon Garden](https://lexicon.garden/lexicon/did:plc:2gqnilpksz2e7faj3bwvo6qc/fyi.opensocial.getGroupAuth)
- [Documentation](https://lexicon.garden/lexicon/did:plc:2gqnilpksz2e7faj3bwvo6qc/fyi.opensocial.getGroupAuth/docs)
- [Examples](https://lexicon.garden/lexicon/did:plc:2gqnilpksz2e7faj3bwvo6qc/fyi.opensocial.getGroupAuth/examples)

## Definitions

### `fyi.opensocial.getGroupAuth`

**Type**: `procedure`

Obtain a DPoP-bound OAuth access token to act as the group DID. The host is the group's PDS and authorization server: the caller authenticates with their personal account (service auth) and presents a DPoP proof; the host issues a short-lived token for the group DID whose space: scopes are exactly what the caller's roles are granted by the space's access record. No group password is involved.

#### Input

**Encoding**: `application/json`

| Property | Type | Required | Description |
|----------|------|----------|-------------|
| `group` | `string` (did) | Yes |  |
| `space` | `string` (space-ref) | Yes | The space the caller intends to write into; its access record's credentialScopes bound the grant. |

#### Output

**Encoding**: `application/json`

| Property | Type | Required | Description |
|----------|------|----------|-------------|
| `accessJwt` | `string` | Yes |  |
| `collections` | `array` | Yes | Collections the caller's roles may write as the group in that space ('*' for any). |
| `did` | `string` (did) | Yes |  |
| `expiresAt` | `string` (datetime) | Yes |  |
| `pds` | `string` (uri) | Yes | Where to use it: the group's PDS (this host). |
| `repoCollections` | `array` | No | Public-repo collections this token may also write. |
| `scope` | `string` | No | The token's OAuth scope string; the PDS enforces it. |

#### Errors

- **Forbidden**

## Raw Schema

```json
{
  "$type": "com.atproto.lexicon.schema",
  "defs": {
    "main": {
      "description": "Obtain a DPoP-bound OAuth access token to act as the group DID. The host is the group's PDS and authorization server: the caller authenticates with their personal account (service auth) and presents a DPoP proof; the host issues a short-lived token for the group DID whose space: scopes are exactly what the caller's roles are granted by the space's access record. No group password is involved.",
      "errors": [
        {
          "name": "Forbidden"
        }
      ],
      "input": {
        "encoding": "application/json",
        "schema": {
          "properties": {
            "group": {
              "format": "did",
              "type": "string"
            },
            "space": {
              "description": "The space the caller intends to write into; its access record's credentialScopes bound the grant.",
              "format": "space-ref",
              "type": "string"
            }
          },
          "required": [
            "group",
            "space"
          ],
          "type": "object"
        }
      },
      "output": {
        "encoding": "application/json",
        "schema": {
          "properties": {
            "accessJwt": {
              "type": "string"
            },
            "collections": {
              "description": "Collections the caller's roles may write as the group in that space ('*' for any).",
              "items": {
                "type": "string"
              },
              "type": "array"
            },
            "did": {
              "format": "did",
              "type": "string"
            },
            "expiresAt": {
              "format": "datetime",
              "type": "string"
            },
            "pds": {
              "description": "Where to use it: the group's PDS (this host).",
              "format": "uri",
              "type": "string"
            },
            "repoCollections": {
              "description": "Public-repo collections this token may also write.",
              "items": {
                "type": "string"
              },
              "type": "array"
            },
            "scope": {
              "description": "The token's OAuth scope string; the PDS enforces it.",
              "type": "string"
            }
          },
          "required": [
            "did",
            "accessJwt",
            "pds",
            "collections",
            "expiresAt"
          ],
          "type": "object"
        }
      },
      "type": "procedure"
    }
  },
  "id": "fyi.opensocial.getGroupAuth",
  "lexicon": 1
}
```
