MenuHost extensions

Procedure · POST

fyi.opensocial.getGroupAuth

A short-lived token for writing as the group in one space.

Obtain a DPoP-bound OAuth access token to act as the group DID. The host is the group's PDS and authorization server: the caller authenticates with their personal account (service auth) and presents a DPoP proof; the host issues a short-lived token for the group DID whose space: scopes are exactly what the caller's roles are granted by the space's access record. No group password is involved.

Requires
a role with credentialScopes in the space

Input

groupstring · didrequired
spacestring · space-refrequired

The space the caller intends to write into; its access record's credentialScopes bound the grant.

Output

didstring · didrequired
accessJwtstringrequired
pdsstring · urirequired

Where to use it: the group's PDS (this host).

collectionsarray of stringrequired

Collections the caller's roles may write as the group in that space ('*' for any).

expiresAtstring · datetimerequired
scopestring

The token's OAuth scope string; the PDS enforces it.

repoCollectionsarray of string

Public-repo collections this token may also write.

Errors

  • Forbidden

Schema

Lexicon JSON
{
  "lexicon": 1,
  "id": "fyi.opensocial.getGroupAuth",
  "defs": {
    "main": {
      "type": "procedure",
      "description": "Obtain a DPoP-bound OAuth access token to act as the group DID. The host is the group's PDS and authorization server: the caller authenticates with their personal account (service auth) and presents a DPoP proof; the host issues a short-lived token for the group DID whose space: scopes are exactly what the caller's roles are granted by the space's access record. No group password is involved.",
      "input": {
        "encoding": "application/json",
        "schema": {
          "type": "object",
          "required": [
            "group",
            "space"
          ],
          "properties": {
            "group": {
              "type": "string",
              "format": "did"
            },
            "space": {
              "type": "string",
              "format": "space-ref",
              "description": "The space the caller intends to write into; its access record's credentialScopes bound the grant."
            }
          }
        }
      },
      "output": {
        "encoding": "application/json",
        "schema": {
          "type": "object",
          "required": [
            "did",
            "accessJwt",
            "pds",
            "collections",
            "expiresAt"
          ],
          "properties": {
            "did": {
              "type": "string",
              "format": "did"
            },
            "accessJwt": {
              "type": "string"
            },
            "pds": {
              "type": "string",
              "format": "uri",
              "description": "Where to use it: the group's PDS (this host)."
            },
            "collections": {
              "type": "array",
              "items": {
                "type": "string"
              },
              "description": "Collections the caller's roles may write as the group in that space ('*' for any)."
            },
            "expiresAt": {
              "type": "string",
              "format": "datetime"
            },
            "scope": {
              "type": "string",
              "description": "The token's OAuth scope string; the PDS enforces it."
            },
            "repoCollections": {
              "type": "array",
              "items": {
                "type": "string"
              },
              "description": "Public-repo collections this token may also write."
            }
          }
        }
      },
      "errors": [
        {
          "name": "Forbidden"
        }
      ]
    }
  }
}

← All host extensions