fyi.opensocial.permissions

lexicons.opensocial.fyi

{
  "$type": "com.atproto.lexicon.schema",
  "defs": {
    "action": {
      "knownValues": [
        "mod.read",
        "mod.resolve",
        "label",
        "takedown",
        "invite",
        "admit",
        "eject",
        "role.assign",
        "space.create",
        "space.configure",
        "space.delete",
        "group.configure"
      ],
      "type": "string"
    },
    "binding": {
      "properties": {
        "actions": {
          "items": {
            "ref": "#action",
            "type": "ref"
          },
          "type": "array"
        },
        "assignable": {
          "description": "For role.assign and eject: the roles this role may grant, revoke, or eject. Absent means none.",
          "items": {
            "description": "A role id: the record key of a fyi.opensocial.role record.",
            "maxLength": 64,
            "type": "string"
          },
          "type": "array"
        },
        "repoCollections": {
          "description": "Collections a holder of this role may write in the group's public repo when acting as the group (signed in as it through an app). '*' for any. Absent means any for a role that holds group.configure, and none otherwise. Writes into the group's spaces are governed by each space's access record instead.",
          "items": {
            "type": "string"
          },
          "type": "array"
        },
        "role": {
          "description": "A role id: the record key of a fyi.opensocial.role record.",
          "maxLength": 64,
          "type": "string"
        }
      },
      "required": [
        "role",
        "actions"
      ],
      "type": "object"
    },
    "main": {
      "description": "The group's authorization config. Binds each role to a set of standardized actions and bounds role.assign and eject. Roles compose by union; there are no deny rules.",
      "key": "literal:self",
      "record": {
        "properties": {
          "bindings": {
            "items": {
              "ref": "#binding",
              "type": "ref"
            },
            "type": "array"
          },
          "createdAt": {
            "format": "datetime",
            "type": "string"
          }
        },
        "required": [
          "bindings",
          "createdAt"
        ],
        "type": "object"
      },
      "type": "record"
    }
  },
  "id": "fyi.opensocial.permissions",
  "lexicon": 1
}

Validate Record

Validate a record against fyi.opensocial.permissions

Validation Options
Treat any remaining unresolved references as valid

Metadata

DID
did:plc:2gqnilpksz2e7faj3bwvo6qc
CID
bafyreidqh5uo7ampcj45fgprkj7dpk3fnl7mo5ohk2gsmzptsjz5ndhteq
Indexed At
2026-09-25 03:15 UTC
AT-URI
at://did:plc:2gqnilpksz2e7faj3bwvo6qc/com.atproto.lexicon.schema/fyi.opensocial.permissions

Version History (2 versions)

Similar Lexicons

Lexicons whose schemas describe something close to this one. Check them before publishing a new one that overlaps.

  • Who may read this space. Present in every space under the group. The group authority issues space credentials according to this record and nothing else.

  • Create or update a role and its action bindings. Requires group.configure.

  • dk.raakode.lab.groups.membership recordnot from the namespace authority

    A member's role in the group. Written by the group authority into its repo in the space, never held as app database state — this is what makes a role survive the group changing app. The simplespace member list governs…

  • Roles, who holds them, the authz config, and the space index. Usually gated to members.

  • Grants a member their roles. Written by the group authority; the record key is the member's DID.

Lexicon Garden

@