# SharedGraph Developers - [Introduction](https://docs.sharedgraph.com/introduction.md): One social network, independently operated applications. - [First public read](https://docs.sharedgraph.com/quickstart.md): Read the public feed with curl and no credentials. - [Concepts and vocabulary](https://docs.sharedgraph.com/concepts.md): The shared model of accounts, actors, applications and social records. - [Register an application](https://docs.sharedgraph.com/registration.md): Request controlled admission for a server-backed confidential client. - [Cloudflare starter](https://docs.sharedgraph.com/starter-guide.md): Run a confidential application and create your first network post. - [Authorization](https://docs.sharedgraph.com/authorization.md): Bind a confidential application to the user's canonical actor. - [Scopes](https://docs.sharedgraph.com/scopes.md): Request only the capabilities your application needs. - [Lifecycle and safety](https://docs.sharedgraph.com/lifecycle-and-safety.md): Retire stale authority and publish only currently admitted network views. - [Errors and client reactions](https://docs.sharedgraph.com/errors.md): Handle domain refusals, OAuth errors and temporary unavailability. - [Anonymous limits](https://docs.sharedgraph.com/limits.md): Per-address budgets and how to handle throttling. - [Changelog](https://docs.sharedgraph.com/changelog.md): Pilot API and integration changes. - [Read a post](https://docs.sharedgraph.com/api-reference/social/read-a-post.md): Read a post. Required scope with bearer authority: `read`. - [Delete your post](https://docs.sharedgraph.com/api-reference/social/delete-your-post.md): Delete your post. Required scope with bearer authority: `post:delete`. Mutations carry intentId in the JSON body. Retry the exact same action with its original intentId; a different payload with that identifier returns intent_conflict. Bearer social calls may omit Origin; if supplied it must exactly… - [Edit your post](https://docs.sharedgraph.com/api-reference/social/edit-your-post.md): Edit your post. Required scope with bearer authority: `post:edit`. Mutations carry intentId in the JSON body. Retry the exact same action with its original intentId; a different payload with that identifier returns intent_conflict. Bearer social calls may omit Origin; if supplied it must exactly mat… - [Read direct replies](https://docs.sharedgraph.com/api-reference/social/read-direct-replies.md): Read direct replies. Required scope with bearer authority: `read`. - [Read the public or following feed](https://docs.sharedgraph.com/api-reference/social/read-the-public-or-following-feed.md): Read the public or following feed. Required scope with bearer authority: `read`. - [Read visible relations](https://docs.sharedgraph.com/api-reference/social/read-visible-relations.md): Read visible relations. Required scope with bearer authority: `read`. - [Read network events](https://docs.sharedgraph.com/api-reference/social/read-network-events.md): Read network events. Required scope with bearer authority: `read`. - [Replace a network view](https://docs.sharedgraph.com/api-reference/social/replace-a-network-view.md): Replace a network view. Required scope with bearer authority: `read`. - [Bind a grant to its actor](https://docs.sharedgraph.com/api-reference/social/bind-a-grant-to-its-actor.md): Bind a grant to its actor. - [Read your network blocks](https://docs.sharedgraph.com/api-reference/social/read-your-network-blocks.md): Read your network blocks. Required scope with bearer authority: `block:read`. - [Read your notification inbox](https://docs.sharedgraph.com/api-reference/social/read-your-notification-inbox.md): Read your notification inbox. Required scope with bearer authority: `inbox:read`. - [Create a post or reply](https://docs.sharedgraph.com/api-reference/social/create-a-post-or-reply.md): Create a post or reply. Required scope with bearer authority: `post:create`. Mutations carry intentId in the JSON body. Retry the exact same action with its original intentId; a different payload with that identifier returns intent_conflict. Bearer social calls may omit Origin; if supplied it must e… - [Mark a notification read](https://docs.sharedgraph.com/api-reference/social/mark-a-notification-read.md): Mark a notification read. Required scope with bearer authority: `inbox:write`. Mutations carry intentId in the JSON body. Retry the exact same action with its original intentId; a different payload with that identifier returns intent_conflict. Bearer social calls may omit Origin; if supplied it must… - [Submit a confidential report](https://docs.sharedgraph.com/api-reference/social/submit-a-confidential-report.md): Submit a confidential report. Required scope with bearer authority: `report:write`. Mutations carry intentId in the JSON body. Retry the exact same action with its original intentId; a different payload with that identifier returns intent_conflict. Bearer social calls may omit Origin; if supplied it… - [Add a follow](https://docs.sharedgraph.com/api-reference/social/add-a-follow.md): Add a follow. Required scope with bearer authority: `follow:write`. Mutations carry intentId in the JSON body. Retry the exact same action with its original intentId; a different payload with that identifier returns intent_conflict. Bearer social calls may omit Origin; if supplied it must exactly ma… - [Remove a follow](https://docs.sharedgraph.com/api-reference/social/remove-a-follow.md): Remove a follow. Required scope with bearer authority: `follow:write`. Mutations carry intentId in the JSON body. Retry the exact same action with its original intentId; a different payload with that identifier returns intent_conflict. Bearer social calls may omit Origin; if supplied it must exactly… - [Add a like](https://docs.sharedgraph.com/api-reference/social/add-a-like.md): Add a like. Required scope with bearer authority: `like:write`. Mutations carry intentId in the JSON body. Retry the exact same action with its original intentId; a different payload with that identifier returns intent_conflict. Bearer social calls may omit Origin; if supplied it must exactly match… - [Remove a like](https://docs.sharedgraph.com/api-reference/social/remove-a-like.md): Remove a like. Required scope with bearer authority: `like:write`. Mutations carry intentId in the JSON body. Retry the exact same action with its original intentId; a different payload with that identifier returns intent_conflict. Bearer social calls may omit Origin; if supplied it must exactly mat… - [Add a block](https://docs.sharedgraph.com/api-reference/social/add-a-block.md): Add a block. Required scope with bearer authority: `block:write`. Mutations carry intentId in the JSON body. Retry the exact same action with its original intentId; a different payload with that identifier returns intent_conflict. Bearer social calls may omit Origin; if supplied it must exactly matc… - [Remove a block](https://docs.sharedgraph.com/api-reference/social/remove-a-block.md): Remove a block. Required scope with bearer authority: `block:write`. Mutations carry intentId in the JSON body. Retry the exact same action with its original intentId; a different payload with that identifier returns intent_conflict. Bearer social calls may omit Origin; if supplied it must exactly m… - [Discover authorization metadata](https://docs.sharedgraph.com/api-reference/discovery/discover-authorization-metadata.md): Discover authorization metadata. - [Discover authorization metadata](https://docs.sharedgraph.com/api-reference/discovery/discover-authorization-metadata-1.md): Discover authorization metadata. - [Discover authorization metadata](https://docs.sharedgraph.com/api-reference/discovery/discover-authorization-metadata-2.md): Discover authorization metadata. - [Discover authorization metadata](https://docs.sharedgraph.com/api-reference/discovery/discover-authorization-metadata-3.md): Discover authorization metadata. - [Discover authorization metadata](https://docs.sharedgraph.com/api-reference/discovery/discover-authorization-metadata-4.md): Discover authorization metadata. - [Read public signing keys](https://docs.sharedgraph.com/api-reference/discovery/read-public-signing-keys.md): Read public signing keys. - [Start authorization code with PKCE](https://docs.sharedgraph.com/api-reference/oauth/start-authorization-code-with-pkce.md): Browser navigation to the provider. An account login and deliberate consent are required before a code is issued. The account cookie is provider UI authority, never social API authority. Use a confidential server-backed client, exact registered redirect URI, S256 PKCE, state and nonce. Resources are… - [Start authorization code with PKCE](https://docs.sharedgraph.com/api-reference/oauth/start-authorization-code-with-pkce-1.md): Browser navigation to the provider. An account login and deliberate consent are required before a code is issued. The account cookie is provider UI authority, never social API authority. Use a confidential server-backed client, exact registered redirect URI, S256 PKCE, state and nonce. Resources are… - [Exchange a code or rotate a refresh token](https://docs.sharedgraph.com/api-reference/oauth/exchange-a-code-or-rotate-a-refresh-token.md): Confidential client authentication uses client_secret_basic (HTTP Basic). Account cookies and social bearer credentials do not authenticate the client. Origin may be omitted; if supplied it must match exactly. Access tokens live 300 seconds; refresh tokens 30 days. Rotation is strict: never reuse a… - [Inspect a credential](https://docs.sharedgraph.com/api-reference/oauth/inspect-a-credential.md): Confidential client authentication uses client_secret_basic (HTTP Basic). Account cookies and social bearer credentials do not authenticate the client. Origin may be omitted; if supplied it must match exactly. - [Revoke a credential](https://docs.sharedgraph.com/api-reference/oauth/revoke-a-credential.md): Confidential client authentication uses client_secret_basic (HTTP Basic). Account cookies and social bearer credentials do not authenticate the client. Origin may be omitted; if supplied it must match exactly. - [Read pairwise identity claims](https://docs.sharedgraph.com/api-reference/oauth/read-pairwise-identity-claims.md): The subject is pairwise and differs from the canonical actor. Bind the actor using /api/session. GET bearer transport only. Required scope with bearer authority: `openid`. - [Provider consent](https://docs.sharedgraph.com/api-reference/oauth/provider-consent.md): Provider browser-flow helper requiring an authenticated maintained account cookie. This is not social bearer authority. POST requires exact network Origin; clients normally reach it through the first-party consent UI. - [Provider continue](https://docs.sharedgraph.com/api-reference/oauth/provider-continue.md): Provider browser-flow helper requiring an authenticated maintained account cookie. This is not social bearer authority. POST requires exact network Origin; clients normally reach it through the first-party consent UI. - [Provider public-client](https://docs.sharedgraph.com/api-reference/oauth/provider-public-client.md): Provider browser-flow helper requiring an authenticated maintained account cookie. This is not social bearer authority. POST requires exact network Origin; clients normally reach it through the first-party consent UI. ## OpenAPI Specs - [openapi](/openapi.json) This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.