fyi.opensocial.provisionGroup

lexicons.opensocial.fyi

{
  "$type": "com.atproto.lexicon.schema",
  "defs": {
    "main": {
      "description": "Host-level: an app creates a group for a person and gets its own OAuth session on it. Authenticated twice: the person asking, by service auth from their PDS (they become the founder), and the app, by OAuth client authentication in the body (a client assertion for a confidential client) with a DPoP proof in the `DPoP` header, exactly as at the token endpoint. The app must be one this host provisions for. Returns the group and a token response bound to the proof's key, issued to the app's client id: refreshed, listed and revoked like any other session on the group.",
      "errors": [
        {
          "name": "UntrustedApp"
        },
        {
          "name": "InvalidScope"
        },
        {
          "name": "use_dpop_nonce"
        },
        {
          "name": "HandleTaken"
        }
      ],
      "input": {
        "encoding": "application/json",
        "schema": {
          "properties": {
            "client_assertion": {
              "type": "string"
            },
            "client_assertion_type": {
              "type": "string"
            },
            "client_id": {
              "type": "string"
            },
            "description": {
              "maxGraphemes": 300,
              "maxLength": 3000,
              "type": "string"
            },
            "displayName": {
              "maxGraphemes": 64,
              "maxLength": 640,
              "type": "string"
            },
            "handle": {
              "format": "handle",
              "type": "string"
            },
            "joinPolicy": {
              "type": "string"
            },
            "metaReadableBy": {
              "items": {
                "type": "string"
              },
              "type": "array"
            },
            "scope": {
              "description": "The OAuth scope the app wants on the group. Must include `atproto`, and every entry must be one the app's client metadata declares.",
              "type": "string"
            },
            "stewards": {
              "description": "Accounts that run the group alongside the founder.",
              "items": {
                "format": "did",
                "type": "string"
              },
              "type": "array"
            }
          },
          "required": [
            "handle",
            "displayName",
            "scope",
            "client_id"
          ],
          "type": "object"
        }
      },
      "output": {
        "encoding": "application/json",
        "schema": {
          "properties": {
            "did": {
              "format": "did",
              "type": "string"
            },
            "members": {
              "format": "space-ref",
              "type": "string"
            },
            "meta": {
              "format": "space-ref",
              "type": "string"
            },
            "session": {
              "description": "An OAuth token response (access_token, token_type, refresh_token, expires_in, scope, sub), as /oauth/token returns it.",
              "type": "unknown"
            }
          },
          "required": [
            "did",
            "meta",
            "members",
            "session"
          ],
          "type": "object"
        }
      },
      "type": "procedure"
    }
  },
  "id": "fyi.opensocial.provisionGroup",
  "lexicon": 1
}

Validate Record

Validate a record against fyi.opensocial.provisionGroup

Validation Options
Treat any remaining unresolved references as valid

Metadata

DID
did:plc:2gqnilpksz2e7faj3bwvo6qc
CID
bafyreiforigy5s65meyirawwafzivbzod6syryksqupxee2fhhu3667kzu
Indexed At
2026-09-24 19:21 UTC
AT-URI
at://did:plc:2gqnilpksz2e7faj3bwvo6qc/com.atproto.lexicon.schema/fyi.opensocial.provisionGroup

Similar Lexicons

Lexicons whose schemas describe something close to this one. Check them before publishing a new one that overlaps.

  • Host-level: create a new group on this host. Authenticated as the founder (service auth from their PDS). The founder and any listed stewards become its first admins. Mints the group DID, creates the meta and members spa…

  • Obtain a DPoP-bound OAuth access token to act as the group DID. The host is the group's PDS and authorization server: the caller authenticates with their personal account (service auth) and presents a DPoP proof; the ho…

Lexicon Garden

@