fyi.opensocial.provisionGroup

lexicons.opensocial.fyi

Documentation

Host-level: an app creates a group for a person and gets its own OAuth session on it. Authenticated twice: the person asking, by service auth from their PDS (they become the founder), and the app, by OAuth client authentication in the body (a client assertion for a confidential client) with a DPoP proof in the `DPoP` header, exactly as at the token endpoint. The app must be one this host provisions for. Returns the group and a token response bound to the proof's key, issued to the app's client id: refreshed, listed and revoked like any other session on the group.

main procedure

Host-level: an app creates a group for a person and gets its own OAuth session on it. Authenticated twice: the person asking, by service auth from their PDS (they become the founder), and the app, by OAuth client authentication in the body (a client assertion for a confidential client) with a DPoP proof in the `DPoP` header, exactly as at the token endpoint. The app must be one this host provisions for. Returns the group and a token response bound to the proof's key, issued to the app's client id: refreshed, listed and revoked like any other session on the group.

Input

Encodingapplication/json
client_assertion string Optional

No description available.

client_assertion_type string Optional

No description available.

client_id string Required

No description available.

description string Optional

No description available.

maxLength: 3000 bytesmaxGraphemes: 300 graphemes
displayName string Required

No description available.

maxLength: 640 bytesmaxGraphemes: 64 graphemes
handle stringhandle Required

An AT Protocol handle (e.g., alice.bsky.social).

joinPolicy string Optional

No description available.

metaReadableBy array Optional

No description available.

scope string Required

The OAuth scope the app wants on the group. Must include `atproto`, and every entry must be one the app's client metadata declares.

stewards array Optional

Accounts that run the group alongside the founder.

Output

Encodingapplication/json
did stringdid Required

A decentralized identifier (DID).

members stringspace-ref Required

No description available.

meta stringspace-ref Required

No description available.

session unknown Required

An OAuth token response (access_token, token_type, refresh_token, expires_in, scope, sub), as /oauth/token returns it.

Errors

UntrustedApp
InvalidScope
use_dpop_nonce
HandleTaken
Try It

Requests are sent directly from your browser. Some servers may block requests due to CORS.

Base URL for XRPC calls (e.g., https://bsky.social)
Enter valid JSON for the request body
View raw schema
{
  "description": "Host-level: an app creates a group for a person and gets its own OAuth session on it. Authenticated twice: the person asking, by service auth from their PDS (they become the founder), and the app, by OAuth client authentication in the body (a client assertion for a confidential client) with a DPoP proof in the `DPoP` header, exactly as at the token endpoint. The app must be one this host provisions for. Returns the group and a token response bound to the proof's key, issued to the app's client id: refreshed, listed and revoked like any other session on the group.",
  "errors": [
    {
      "name": "UntrustedApp"
    },
    {
      "name": "InvalidScope"
    },
    {
      "name": "use_dpop_nonce"
    },
    {
      "name": "HandleTaken"
    }
  ],
  "input": {
    "encoding": "application/json",
    "schema": {
      "properties": {
        "client_assertion": {
          "type": "string"
        },
        "client_assertion_type": {
          "type": "string"
        },
        "client_id": {
          "type": "string"
        },
        "description": {
          "maxGraphemes": 300,
          "maxLength": 3000,
          "type": "string"
        },
        "displayName": {
          "maxGraphemes": 64,
          "maxLength": 640,
          "type": "string"
        },
        "handle": {
          "format": "handle",
          "type": "string"
        },
        "joinPolicy": {
          "type": "string"
        },
        "metaReadableBy": {
          "items": {
            "type": "string"
          },
          "type": "array"
        },
        "scope": {
          "description": "The OAuth scope the app wants on the group. Must include `atproto`, and every entry must be one the app's client metadata declares.",
          "type": "string"
        },
        "stewards": {
          "description": "Accounts that run the group alongside the founder.",
          "items": {
            "format": "did",
            "type": "string"
          },
          "type": "array"
        }
      },
      "required": [
        "handle",
        "displayName",
        "scope",
        "client_id"
      ],
      "type": "object"
    }
  },
  "output": {
    "encoding": "application/json",
    "schema": {
      "properties": {
        "did": {
          "format": "did",
          "type": "string"
        },
        "members": {
          "format": "space-ref",
          "type": "string"
        },
        "meta": {
          "format": "space-ref",
          "type": "string"
        },
        "session": {
          "description": "An OAuth token response (access_token, token_type, refresh_token, expires_in, scope, sub), as /oauth/token returns it.",
          "type": "unknown"
        }
      },
      "required": [
        "did",
        "meta",
        "members",
        "session"
      ],
      "type": "object"
    }
  },
  "type": "procedure"
}

Lexicon Garden

@