fyi.opensocial.provisionGroup
{
"$type": "com.atproto.lexicon.schema",
"defs": {
"main": {
"description": "Host-level: an app creates a group for a person and gets its own OAuth session on it. Authenticated twice: the person asking, by service auth from their PDS (they become the founder), and the app, by OAuth client authentication in the body (a client assertion for a confidential client) with a DPoP proof in the `DPoP` header, exactly as at the token endpoint. The app must be one this host provisions for. Returns the group and a token response bound to the proof's key, issued to the app's client id: refreshed, listed and revoked like any other session on the group.",
"errors": [
{
"name": "UntrustedApp"
},
{
"name": "InvalidScope"
},
{
"name": "use_dpop_nonce"
},
{
"name": "HandleTaken"
}
],
"input": {
"encoding": "application/json",
"schema": {
"properties": {
"client_assertion": {
"type": "string"
},
"client_assertion_type": {
"type": "string"
},
"client_id": {
"type": "string"
},
"description": {
"maxGraphemes": 300,
"maxLength": 3000,
"type": "string"
},
"displayName": {
"maxGraphemes": 64,
"maxLength": 640,
"type": "string"
},
"handle": {
"format": "handle",
"type": "string"
},
"joinPolicy": {
"type": "string"
},
"metaReadableBy": {
"items": {
"type": "string"
},
"type": "array"
},
"scope": {
"description": "The OAuth scope the app wants on the group. Must include `atproto`, and every entry must be one the app's client metadata declares.",
"type": "string"
},
"stewards": {
"description": "Accounts that run the group alongside the founder.",
"items": {
"format": "did",
"type": "string"
},
"type": "array"
}
},
"required": [
"handle",
"displayName",
"scope",
"client_id"
],
"type": "object"
}
},
"output": {
"encoding": "application/json",
"schema": {
"properties": {
"did": {
"format": "did",
"type": "string"
},
"members": {
"format": "space-ref",
"type": "string"
},
"meta": {
"format": "space-ref",
"type": "string"
},
"session": {
"description": "An OAuth token response (access_token, token_type, refresh_token, expires_in, scope, sub), as /oauth/token returns it.",
"type": "unknown"
}
},
"required": [
"did",
"meta",
"members",
"session"
],
"type": "object"
}
},
"type": "procedure"
}
},
"id": "fyi.opensocial.provisionGroup",
"lexicon": 1
}
Metadata
- DID
-
did:plc:2gqnilpksz2e7faj3bwvo6qc - CID
-
bafyreiforigy5s65meyirawwafzivbzod6syryksqupxee2fhhu3667kzu - Indexed At
- 2026-09-24 19:21 UTC
- AT-URI
-
at://did:plc:2gqnilpksz2e7faj3bwvo6qc/com.atproto.lexicon.schema/fyi.opensocial.provisionGroup
Similar Lexicons
Lexicons whose schemas describe something close to this one. Check them before publishing a new one that overlaps.
-
fyi.opensocial.createGroup procedure
Host-level: create a new group on this host. Authenticated as the founder (service auth from their PDS). The founder and any listed stewards become its first admins. Mints the group DID, creates the meta and members spa…
-
fyi.opensocial.getGroupAuth procedure
Obtain a DPoP-bound OAuth access token to act as the group DID. The host is the group's PDS and authorization server: the caller authenticates with their personal account (service auth) and presents a DPoP proof; the ho…