Host-level: an app creates a group for a person and gets its own OAuth session on it. Authenticated twice: the person asking, by service auth from their PDS (they become the founder), and the app, by OAuth client authentication in the body (a client assertion for a confidential client) with a DPoP proof in the `DPoP` header, exactly as at the token endpoint. The app must be one this host provisions for. Returns the group and a token response bound to the proof's key, issued to the app's client id: refreshed, listed and revoked like any other session on the group.
Input
application/jsonclient_assertion
string
Optional
No description available.
client_assertion_type
string
Optional
No description available.
client_id
string
Required
No description available.
description
string
Optional
No description available.
maxLength: 3000 bytesmaxGraphemes: 300 graphemesdisplayName
string
Required
No description available.
maxLength: 640 bytesmaxGraphemes: 64 graphemeshandle
stringhandle
Required
An AT Protocol handle (e.g., alice.bsky.social).
joinPolicy
string
Optional
No description available.
metaReadableBy
array
Optional
No description available.
scope
string
Required
The OAuth scope the app wants on the group. Must include `atproto`, and every entry must be one the app's client metadata declares.
stewards
array
Optional
Accounts that run the group alongside the founder.
Output
application/jsondid
stringdid
Required
A decentralized identifier (DID).
members
stringspace-ref
Required
No description available.
meta
stringspace-ref
Required
No description available.
session
unknown
Required
An OAuth token response (access_token, token_type, refresh_token, expires_in, scope, sub), as /oauth/token returns it.
Errors
UntrustedApp
InvalidScope
use_dpop_nonce
HandleTaken
Try It
Requests are sent directly from your browser. Some servers may block requests due to CORS.
View raw schema
{
"description": "Host-level: an app creates a group for a person and gets its own OAuth session on it. Authenticated twice: the person asking, by service auth from their PDS (they become the founder), and the app, by OAuth client authentication in the body (a client assertion for a confidential client) with a DPoP proof in the `DPoP` header, exactly as at the token endpoint. The app must be one this host provisions for. Returns the group and a token response bound to the proof's key, issued to the app's client id: refreshed, listed and revoked like any other session on the group.",
"errors": [
{
"name": "UntrustedApp"
},
{
"name": "InvalidScope"
},
{
"name": "use_dpop_nonce"
},
{
"name": "HandleTaken"
}
],
"input": {
"encoding": "application/json",
"schema": {
"properties": {
"client_assertion": {
"type": "string"
},
"client_assertion_type": {
"type": "string"
},
"client_id": {
"type": "string"
},
"description": {
"maxGraphemes": 300,
"maxLength": 3000,
"type": "string"
},
"displayName": {
"maxGraphemes": 64,
"maxLength": 640,
"type": "string"
},
"handle": {
"format": "handle",
"type": "string"
},
"joinPolicy": {
"type": "string"
},
"metaReadableBy": {
"items": {
"type": "string"
},
"type": "array"
},
"scope": {
"description": "The OAuth scope the app wants on the group. Must include `atproto`, and every entry must be one the app's client metadata declares.",
"type": "string"
},
"stewards": {
"description": "Accounts that run the group alongside the founder.",
"items": {
"format": "did",
"type": "string"
},
"type": "array"
}
},
"required": [
"handle",
"displayName",
"scope",
"client_id"
],
"type": "object"
}
},
"output": {
"encoding": "application/json",
"schema": {
"properties": {
"did": {
"format": "did",
"type": "string"
},
"members": {
"format": "space-ref",
"type": "string"
},
"meta": {
"format": "space-ref",
"type": "string"
},
"session": {
"description": "An OAuth token response (access_token, token_type, refresh_token, expires_in, scope, sub), as /oauth/token returns it.",
"type": "unknown"
}
},
"required": [
"did",
"meta",
"members",
"session"
],
"type": "object"
}
},
"type": "procedure"
}