MenuHost extensions

Host extensions

What the reference host serves beyond the proposal that apps need today. Not part of the standard, so they keep their published fyi.opensocial names.

The proposal specifies the interface between groups and apps, but building real apps turned up a few things it doesn’t cover yet. The reference host serves them, and the Build an app guides use every one.

They aren’t part of the standard, so they keep their published fyi.opensocial.* names instead of group.opensocial.*.

NameKindPurpose
fyi.opensocial.listGroupsmethodThe groups on a host, with public profiles. For signed-out pages.
fyi.opensocial.getGroupAuthmethodA short-lived token for writing as the group in one space.
fyi.opensocial.getJoinRequestmethodThe caller's own pending join request, if any.
fyi.opensocial.provisionGroupmethodCreate a group for a person and get the app a session on it.
fyi.opensocial.basePermissionspermission setThe permission set every group app asks for.

Why each one exists

  • listGroups: a space can’t be read without signing in, even a public one. Signed-out pages need some way to show a group’s profile. It goes away once public spaces can be read anonymously.
  • getGroupAuth: the proposal describes writing as the group with an OAuth credential for the group DID. This gets one for a single space from a member’s own session, without a separate sign-in.
  • getJoinRequest: the proposal has requestJoin and cancelJoinRequest, but no way for a person to read back whether their request is still pending.
  • provisionGroup: lets an app start a group for a person and get its own session on it, so the founder never leaves the app.
  • basePermissions: the permission set every group app asks for. It covers the standard’s spaces and the host methods an app calls, which a set can only grant for names under its own.

Not listed here

The reference host serves more, but ordinary apps don’t need it:

  • Running a group: createGroup (without a session), listGroupTokens and revokeGroupToken (connected apps), deactivateGroup, activateGroup, deleteGroup, recovery keys and migration between hosts. These are for group consoles and hosts.
  • Shared data between apps: the calendar’s space type and permission set aren’t host features. They’re under Shared modalities.

The schemas in the table above are also in llms-full.txt.