social.colibri.beta.actor.grantSpaceAccess

colibri.social

{
  "$type": "com.atproto.lexicon.schema",
  "defs": {
    "main": {
      "description": "Hands the AppView access to one of the requesting user's personal spaces. The client mints a delegation token on its own PDS for the space and passes it here, because a delegation token is single-use and short-lived and the AppView has no OAuth session of its own. The AppView exchanges the token for a space credential and syncs the space.",
      "errors": [
        {
          "description": "The request has no valid service auth.",
          "name": "AuthRequired"
        },
        {
          "description": "The arguments are inconsistent or malformed beyond schema validation.",
          "name": "InvalidRequest"
        },
        {
          "description": "The delegation token is malformed, expired, or already used.",
          "name": "InvalidDelegationToken"
        },
        {
          "description": "No space matches the given space reference.",
          "name": "SpaceNotFound"
        },
        {
          "description": "The delegation token does not grant access to the given space.",
          "name": "NotAuthorized"
        },
        {
          "description": "The user's PDS failed while the AppView exchanged the delegation token or synced the space.",
          "name": "UpstreamFailure"
        }
      ],
      "input": {
        "encoding": "application/json",
        "schema": {
          "properties": {
            "delegationToken": {
              "description": "A delegation token minted by the user's PDS for the space.",
              "type": "string"
            },
            "space": {
              "description": "The space to grant access to.",
              "format": "space-ref",
              "type": "string"
            }
          },
          "required": [
            "space",
            "delegationToken"
          ],
          "type": "object"
        }
      },
      "output": {
        "encoding": "application/json",
        "schema": {
          "properties": {
            "expiresAt": {
              "description": "When the resulting space credential expires. The client should call this again before then to keep access current.",
              "format": "datetime",
              "type": "string"
            }
          },
          "required": [
            "expiresAt"
          ],
          "type": "object"
        }
      },
      "type": "procedure"
    }
  },
  "id": "social.colibri.beta.actor.grantSpaceAccess",
  "lexicon": 1
}

Validate Record

Validate a record against social.colibri.beta.actor.grantSpaceAccess

Validation Options
Treat any remaining unresolved references as valid

Metadata

DID
did:plc:mprdjqjluoswa7awzggaggj3
CID
bafyreibl4mungi3jhoqlu2jfcaeyaxfpkwrk77ejfob5wldyrpe4u3nbmu
Indexed At
2026-08-23 12:32 UTC
AT-URI
at://did:plc:mprdjqjluoswa7awzggaggj3/com.atproto.lexicon.schema/social.colibri.beta.actor.grantSpaceAccess

Similar Lexicons

Lexicons whose schemas describe something close to this one. Check them before publishing a new one that overlaps.

  • Give bard a delegation token so it can keep reading a space. Any member can call this with a token they issued. Bard trades it for a credential, renews its notification registration when due, and catches up on anything …

  • Connect a space so bard can read and publish the authority's site and tile records from it. Only the authority can call this, with a delegation token it issued. Bard trades the token for a credential, registers for noti…

  • Issue a space credential (JWT) for a space the caller is a member of. The credential is multi-use until it expires and is bound to the caller's DPoP key (cnf.jkt, RFC 9449): it must be presented under the DPoP auth sche…

  • Obtain a DPoP-bound OAuth access token to act as the group DID. The host is the group's PDS and authorization server: the caller authenticates with their personal account (service auth) and presents a DPoP proof; the ho…

Lexicon Garden

@