Procedure · POST
fyi.opensocial.getGroupAuth
A short-lived token for writing as the group in one space.
Obtain a DPoP-bound OAuth access token to act as the group DID. The host is the group's PDS and authorization server: the caller authenticates with their personal account (service auth) and presents a DPoP proof; the host issues a short-lived token for the group DID whose space: scopes are exactly what the caller's roles are granted by the space's access record. No group password is involved.
- Requires
a role with credentialScopes in the space
Input
groupstring · didrequiredspacestring · space-refrequiredThe space the caller intends to write into; its access record's credentialScopes bound the grant.
Output
didstring · didrequiredaccessJwtstringrequiredpdsstring · urirequiredWhere to use it: the group's PDS (this host).
collectionsarray of stringrequiredCollections the caller's roles may write as the group in that space ('*' for any).
expiresAtstring · datetimerequiredscopestringThe token's OAuth scope string; the PDS enforces it.
repoCollectionsarray of stringPublic-repo collections this token may also write.
Errors
Forbidden
Schema
Lexicon JSON
{
"lexicon": 1,
"id": "fyi.opensocial.getGroupAuth",
"defs": {
"main": {
"type": "procedure",
"description": "Obtain a DPoP-bound OAuth access token to act as the group DID. The host is the group's PDS and authorization server: the caller authenticates with their personal account (service auth) and presents a DPoP proof; the host issues a short-lived token for the group DID whose space: scopes are exactly what the caller's roles are granted by the space's access record. No group password is involved.",
"input": {
"encoding": "application/json",
"schema": {
"type": "object",
"required": [
"group",
"space"
],
"properties": {
"group": {
"type": "string",
"format": "did"
},
"space": {
"type": "string",
"format": "space-ref",
"description": "The space the caller intends to write into; its access record's credentialScopes bound the grant."
}
}
}
},
"output": {
"encoding": "application/json",
"schema": {
"type": "object",
"required": [
"did",
"accessJwt",
"pds",
"collections",
"expiresAt"
],
"properties": {
"did": {
"type": "string",
"format": "did"
},
"accessJwt": {
"type": "string"
},
"pds": {
"type": "string",
"format": "uri",
"description": "Where to use it: the group's PDS (this host)."
},
"collections": {
"type": "array",
"items": {
"type": "string"
},
"description": "Collections the caller's roles may write as the group in that space ('*' for any)."
},
"expiresAt": {
"type": "string",
"format": "datetime"
},
"scope": {
"type": "string",
"description": "The token's OAuth scope string; the PDS enforces it."
},
"repoCollections": {
"type": "array",
"items": {
"type": "string"
},
"description": "Public-repo collections this token may also write."
}
}
}
},
"errors": [
{
"name": "Forbidden"
}
]
}
}
}