<https://docs.linkeddatahub.com/reference/dataspace/#content>
        a       <https://w3id.org/atomgraph/linkeddatahub#XHTML>;
        <http://www.w3.org/1999/02/22-rdf-syntax-ns#value>
                "<div xmlns=\"http://www.w3.org/1999/xhtml\">\n    <p class=\"ldh-body-lg\">LinkedDataHub dataspaces and services</p>\n    <div>\n        <h2 id=\"dataspaces\">Dataspaces</h2>\n        <p>The LinkedDataHub URI address space is split into <dfn>dataspaces</dfn>. A dataspace is identified by its <dfn>origin</dfn> — scheme, host and port — and\n            every resource it serves is relative to that origin. A single LinkedDataHub instance serves as many dataspaces as are configured, each on its own origin.</p>\n        <p>Every dataspace has the following traits:</p>\n        <dl>\n            <dt>Base URI</dt>\n            <dd>The URI that identifies the dataspace. All request URIs it processes are relative to it.</dd>\n            <dd>URIs in the <a href=\"../dataset/\">dataspace's dataset</a> are usually (but not necessarily) relative to its base URI.</dd>\n            <dt>Service</dt>\n            <dd><a href=\"#services\">SPARQL service</a> the dataspace's dataset is stored in</dd>\n            <dt>Namespace ontology</dt>\n            <dd><a href=\"../administration/ontologies/#ontologies\">Ontology</a> that defines the terms (classes, properties, constraints etc.) of the dataspace's domain. It can import\n                other ontologies from within the dataspace as well as from external documents.</dd>\n            <dd>Ontologies are <a href=\"../administration/ontologies/\">managed in the administration dataspace</a>.</dd>\n            <dt>Stylesheet</dt>\n            <dd>The <a href=\"../stylesheets/\" target=\"_blank\">XSLT stylesheet</a> that renders the dataspace's layout</dd>\n        </dl>\n        <div class=\"ac-alert va-informative\" role=\"status\">\n            <span class=\"ac-alert-ic\"><span aria-hidden=\"true\" class=\"msi outline\">info</span></span>\n            <div class=\"ac-alert-body\">\n                <p class=\"ac-alert-text\">Base URI must end with a forward slash (<code>/</code>).</p>\n            </div>\n        </div>\n        <p>The <a href=\"../administration/acl/#agents\">agent</a> that installed the dataspace's dataset is its <dfn>owner</dfn>. The <dfn>secretary</dfn> is a special agent\n            which represents the software itself; it is distinct from the owner agent and is used to delegate the owner's access.</p>\n        <p>LinkedDataHub imports the <a href=\"../dataset/#default-datasets\">default datasets</a> for each kind of dataspace into its service. The dataset URIs are rebased\n            to be relative to the base URI of the dataspace.</p>\n        <p>Each dataspace's data is structured as a hierarchy of containers and items — see the\n            <a href=\"../data-model/documents/#hierarchy\" target=\"_blank\">document hierarchy reference</a> for details and the\n            <a href=\"../data-model/documents/#management\" target=\"_blank\">management actions</a> that can be performed on documents.\n            See also the <a href=\"../administration/\">administration reference</a>.</p>\n        <div>\n            <h3 id=\"end-user\">End-user dataspaces</h3>\n            <p>An end-user dataspace serves the domain data: the document hierarchy, its namespace ontology and whatever an agent is authorized to read or write. It is\n                typed <code>lds:EndUserDataspace</code> and is what a visitor reaches at the dataspace's own origin.</p>\n        </div>\n        <div>\n            <h3 id=\"admin\">Administration dataspaces</h3>\n            <p>An administration dataspace provides the means to control the <a href=\"../administration/ontologies/\">domain model</a> and the\n                <a href=\"../administration/acl/\">access control</a> of the end-user dataspace it administers. It is typed <code>lds:AdminDataspace</code>, and only owners\n                have access to it.</p>\n            <p>The two are associated by origin rather than by declaration: an administration dataspace's origin is its end-user dataspace's origin with the\n                <code>admin.</code> subdomain prefixed to the host (e.g. <samp>https://example.com/</samp> → <samp>https://admin.example.com/</samp>), and LinkedDataHub\n                derives the counterpart from the host in either direction. You do not configure the relationship.</p>\n            <div class=\"ac-alert va-informative\" role=\"status\">\n                <span class=\"ac-alert-ic\"><span aria-hidden=\"true\" class=\"msi outline\">info</span></span>\n                <div class=\"ac-alert-body\">\n                    <p class=\"ac-alert-text\">Since LinkedDataHub 5.1.0 the administration dataspace is served on the <code>admin.</code> subdomain rather than under an\n                        <code>admin/</code> path, so it no longer occupies a path within the end-user dataspace. The subdomain must resolve in DNS and be covered by the\n                        server's TLS certificate.</p>\n                </div>\n            </div>\n        </div>\n        <div>\n            <h3 id=\"configuring-dataspaces\">Configuring dataspaces</h3>\n            <p>Dataspaces are configured using RDF files in <a href=\"https://www.w3.org/TR/trig/\" target=\"_blank\">TriG</a> syntax — see the\n                <a href=\"../configuration/#config-files\">configuration reference</a> for the files and their roles.</p>\n            <p>A second dataspace added to <samp>config/dataspaces.trig</samp> — one named graph per dataspace, identified with\n                <code>urn:</code> URIs, the end-user and administration dataspaces associated by the <code>admin.</code> origin prefix. This is the template the\n                <a href=\"../../user-guide/manage-dataspaces/#create-dataspace\">create a dataspace</a> guide refers to; the origins follow the\n                <samp>&lt;app&gt;.demo.&lt;host&gt;</samp> shape the demo site uses, so the same declaration works locally on\n                <samp>localhost:4443</samp> and deployed on a public host:</p>\n            <pre>&lt;urn:linkeddatahub:apps/northwind-traders/end-user&gt;\n{\n    &lt;urn:linkeddatahub:apps/northwind-traders/end-user&gt; a lds:Dataspace ;\n        dct:title \"Northwind Traders\" ;\n        lds:origin &lt;https://northwind-traders.demo.localhost:4443&gt; ;\n        lds:ontology &lt;https://northwind-traders.demo.localhost:4443/ns#&gt; ;\n        ac:stylesheet &lt;https://northwind-traders.demo.localhost:4443/static/xsl/layout.xsl&gt; ;\n        lds:public true .\n}\n\n&lt;urn:linkeddatahub:apps/northwind-traders/admin&gt;\n{\n    &lt;urn:linkeddatahub:apps/northwind-traders/admin&gt; a lds:Dataspace ;\n        dct:title \"Northwind Traders admin\" ;\n        lds:origin &lt;https://admin.northwind-traders.demo.localhost:4443&gt; ;\n        lds:ontology &lt;https://w3id.org/atomgraph/linkeddatahub/admin#&gt; ;\n        ac:stylesheet &lt;https://admin.northwind-traders.demo.localhost:4443/static/xsl/admin/layout.xsl&gt; .\n}</pre>\n            <p>and its service bindings in <samp>config/system.trig</samp>:</p>\n            <pre>&lt;urn:linkeddatahub:apps/northwind-traders/end-user&gt;\n{\n    &lt;urn:linkeddatahub:apps/northwind-traders/end-user&gt; a lds:EndUserDataspace ;\n        lds:service &lt;urn:linkeddatahub:services/end-user&gt; .\n}\n\n&lt;urn:linkeddatahub:apps/northwind-traders/admin&gt;\n{\n    &lt;urn:linkeddatahub:apps/northwind-traders/admin&gt; a lds:AdminDataspace ;\n        lds:service &lt;urn:linkeddatahub:services/admin&gt; .\n}</pre>\n            <p class=\"exhibit-links\">Source: <a href=\"https://github.com/AtomGraph/LinkedDataHub/blob/develop/config/dataspaces.trig\" target=\"_blank\">config/dataspaces.trig</a>, <a href=\"https://github.com/AtomGraph/LinkedDataHub/blob/develop/config/system.trig\" target=\"_blank\">config/system.trig</a> · Live: <a href=\"https://northwind-traders.demo.linkeddatahub.com/\" target=\"_blank\">northwind-traders.demo.linkeddatahub.com</a></p>\n        </div>\n    </div>\n    <div>\n        <h2 id=\"services\">Services</h2>\n        <p>A service is a persistent SPARQL 1.1-compatible store from which a dataspace's <a href=\"../dataset/\">RDF dataset</a> is accessible over HTTP. LinkedDataHub provides\n            generic services as well as triplestore-specific ones, which allow simpler configuration and optimized access.</p>\n        <p>LinkedDataHub works with various SPARQL backends, using <a href=\"https://jena.apache.org/documentation/fuseki2/\" target=\"_blank\">Apache Jena Fuseki</a> by default. See the <a href=\"../triplestores/\">triplestores reference</a> for compatibility requirements and configuration examples.</p>\n        <div class=\"ac-alert va-informative\" role=\"status\">\n            <span class=\"ac-alert-ic\"><span aria-hidden=\"true\" class=\"msi outline\">info</span></span>\n            <div class=\"ac-alert-body\">\n                <p class=\"ac-alert-text\">The end-user and administration services need no federation between them: the platform queries each service on its own, and the\n                stores' outbound <code>SERVICE</code> requests go through the <a href=\"../configuration/#egress\"><samp>egress</samp></a> proxy, which refuses internal destinations —\n                so a query on one dataset cannot reach another.</p>\n            </div>\n        </div>\n        <div>\n            <h3 id=\"generic-services\">Generic services</h3>\n            <p>Generic service has the following properties:</p>\n            <table>\n                <caption class=\"ac-vh\">Service fields and whether each is required</caption>\n                <thead>\n                    <tr>\n                        <th scope=\"col\">Field</th>\n                        <th scope=\"col\">Value</th>\n                        <th scope=\"col\">Required</th>\n                    </tr>\n                </thead>\n                <tbody>\n                    <tr>\n                        <th scope=\"row\">Endpoint</th>\n                        <td>SPARQL 1.1 Protocol endpoint URI</td>\n                        <td>Yes</td>\n                    </tr>\n                    <tr>\n                        <th scope=\"row\">Graph Store</th>\n                        <td>SPARQL 1.1 Graph Store Protocol endpoint URI</td>\n                        <td>Yes</td>\n                    </tr>\n                    <tr>\n                        <th scope=\"row\">Quad Store</th>\n                        <td>Endpoint URI for dataset-level RDF CRUD operations. Without it, LinkedDataHub falls back to graph-scoped Graph Store Protocol.</td>\n                        <td>No</td>\n                    </tr>\n                    <tr>\n                        <th scope=\"row\">Username</th>\n                        <td>HTTP Basic username</td>\n                        <td>No</td>\n                    </tr>\n                    <tr>\n                        <th scope=\"row\">Password</th>\n                        <td>HTTP Basic password</td>\n                        <td>No</td>\n                    </tr>\n                    <tr>\n                        <th scope=\"row\">Auth token</th>\n                        <td>Bearer authentication token, as an alternative to HTTP Basic. Stored in the <a href=\"../configuration/#secrets\"><samp>credentials</samp> secret file</a> under <code>a:authToken</code>.</td>\n                        <td>No</td>\n                    </tr>\n                </tbody>\n            </table>\n            <p>You can use either HTTP Basic authentication (username/password) or Bearer token authentication (auth token), but not both for the same service.</p>\n            <p>Each dataspace has its own end-user and admin service, pointing at its own datasets in the single <a href=\"../configuration/#fuseki\"><samp>fuseki</samp></a> server. A dataset is named after the dataspace origin with the deployment host dropped and the role appended, so the Northwind Traders end-user service reads <samp>northwind-traders.demo.end-user</samp>:</p>\n            <pre>&lt;urn:northwind-traders:services/end-user&gt;\n{\n    &lt;urn:northwind-traders:services/end-user&gt; a sd:Service ;\n        dct:title \"Northwind Traders service\" ;\n        sd:supportedLanguage sd:SPARQL11Query, sd:SPARQL11Update ;\n        sd:endpoint &lt;http://fuseki:3030/northwind-traders.demo.end-user/&gt; ;\n        a:graphStore &lt;http://fuseki:3030/northwind-traders.demo.end-user/&gt; ;\n        a:quadStore &lt;http://fuseki:3030/northwind-traders.demo.end-user/&gt; .\n}</pre>\n            <p>The root dataspace's services keep the plain <samp>end-user</samp> and <samp>admin</samp> dataset names. Several dataspaces may still share one service where isolation is not required.</p>\n            <p class=\"exhibit-links\">Source: <a href=\"https://github.com/AtomGraph/LinkedDataHub/blob/develop/config/system.trig\" target=\"_blank\">config/system.trig</a></p>\n            <div class=\"ac-alert va-informative\" role=\"status\">\n                <span class=\"ac-alert-ic\"><span aria-hidden=\"true\" class=\"msi outline\">info</span></span>\n                <div class=\"ac-alert-body\">\n                    <p class=\"ac-alert-text\">LinkedDataHub has extension points for vendor-specific SPARQL services, which can be used to implement proprietary authentication schemes, for example.</p>\n                </div>\n            </div>\n        </div>\n    </div>\n    <p class=\"ldh-body-lg\">If you are ready to create a dataspace, see the <a href=\"../../user-guide/manage-dataspaces/\">dataspace management</a> user guide.</p>\n</div>"^^<http://www.w3.org/1999/02/22-rdf-syntax-ns#XMLLiteral> .

<https://docs.linkeddatahub.com/reference/dataspace/>
        a       <https://w3id.org/atomgraph/linkeddatahub/document-hierarchy#Item>;
        <http://www.w3.org/1999/02/22-rdf-syntax-ns#_1>
                <https://docs.linkeddatahub.com/reference/dataspace/#content>;
        <http://purl.org/dc/terms/created>
                "2026-09-29T09:52:22.336Z"^^<http://www.w3.org/2001/XMLSchema#dateTime>;
        <http://purl.org/dc/terms/creator>
                <https://admin.linkeddatahub.com/acl/agents/5ba81960-d511-4a3b-8b9a-cb5bb278dd95/#this>;
        <http://purl.org/dc/terms/description>
                "LinkedDataHub dataspaces and services";
        <http://purl.org/dc/terms/title>
                "Dataspace";
        <http://rdfs.org/sioc/ns#has_container>
                <https://docs.linkeddatahub.com/reference/>;
        <http://www.w3.org/ns/auth/acl#owner>
                <https://admin.linkeddatahub.com/acl/agents/5ba81960-d511-4a3b-8b9a-cb5bb278dd95/#this> .
