atproto git client
atgc plan api.md
6.4 kB
Markdown
at main


id: api title: Everything the lexicon has, reachable without a verb for it status: shipped repos: [atgc] dependsOn: [sign-in] exitCriterion: > Any XRPC method a PDS or a Tangled service serves can be called with the right credential, without atgc growing a verb and without a new scope. #

api #

Tangled's lexicon is far larger than the part atgc has verbs for — labels, stars, follows, collaborators, notifications — and none of it was reachable at all. atgc api <nsid> is the hatch.

The design question was which credential, and the answer is that the host decides: --host pds|knot:<hostname>|appview|bobbin. "An XRPC call" is three unrelated acts here — a PDS call under the session's DPoP-bound access token, a knot procedure under a service-auth JWT minted for that one method, a public read under nothing — so a flag naming the credential would ask the user to already know the thing they came here to find out, and a wrong guess would hand a third-party knot a token for the PDS.

It adds no scope, and could not: a scope added to SCOPES is a re-login for every account, and an escape hatch is the last thing that should cost one.

What it needs #

Done #