







Update: The changes described in this blog post have been incorporated into the 2025-06-18 version of the MCP spec!
Enterprise-Managed Authorization: Zero-touch OAuth for MCP
The Enterprise-Managed Authorization extension to the Model Context Protocol is now stable, enabling organizations to centrally provision MCP server access through their identity provider so users get connected servers on first login without per-app OAuth.

OAuth Improvements - AT Protocol
We've been making improvements to the end-user and developer experiences with atproto OAuth.

tilesprivacy/mcp-cli
Interactive CLI client for remote Model Context Protocol (MCP) servers with OAuth 2.0 support.
@atproto/oauth-provider - AT Protocol
OAuth 2.0 and OpenID Connect authorization server for AT Protocol
Cross-App Authentication on AT Protocol
We recently built cross-app authentication between Roomy and OpenMeet using AT Protocol service auth JWTs. The idea came from @erlend.sh (his writeup), @zicklag.dev introduced me to PDS service auth, and @meri.garden contributed reviews. I made the implementation in both apps: A user logs into Roomy, navigates to an OpenMeet event, and is silently authenticated and able to use their account on OpenMeet without a second login. Full technical writeup: Cross-App Authentication on AT Protocol I’m ...

OAuth Roadmap · bluesky-social atproto · Discussion #2656
OAuth is nigh! Protocol support has been a long time coming and we are pumped. It should greatly improve the user and developer experiences building secure apps and integrations on atproto. And cou...
tijs/atproto-oauth
Framework-agnostic OAuth integration for AT Protocol (Bluesky) applications
better-auth-bsky - npmx
A better-auth plugin that adds ATProto/Bluesky OAuth 2.1 authentication (DPoP, PAR, PKCE) via @atcute/oauth-node-client.

OAuth for ATProto Apps Part 2: Mobile Implementation - Lost in Inference
Part 2 of a 2-part series on implementing OAuth authentication for ATProto (Bluesky) applications.
OAuth for AT Protocol | Bluesky
We are very happy to release the initial specification of OAuth for AT Protocol! This is expected to be the primary authentication and authorization system between atproto client apps and PDS instances going forward, replacing the current flow using App Passwords and createSession over time.

@atproto/oauth-client-node - AT Protocol
Node.js OAuth client for AT Protocol with built-in crypto and storage
at the moment they are somewhat far apart (for one it currently has its own PoP mechanism with its own nonces, etc.), but it is still possible! there is a discussion here: github.com/oauth-wg/draft-ietf-oauth-att…
Similar proposal in AT Protocol: DPoP-bound private_key_jwt client authentication · Issue #123 · oauth-wg/draft-ietf-oauth-attestation-based-client-auth
github.comHey @surf.social the atproto early adopter / tech community can’t recommend you until you implement OAuth. This is a pretty big user security issue. Let us know if you need help or contract @thisismissem.social
im'bcmgs'im
surf.social looks amazing but idk about this login experience... i dont normally wanna put my password for one site into another site 🙃
there’s a reason why i added this informational box to the sign in flow for @anisota.net — i wanted to make it clearer that the user is redirected away from anisota and to their own account/PDS… and that anisota isn’t getting their password helps that anisota’s design is SO diff from the oauth page
Kuba Suder 🇵🇱🇺🇦
I think Bluesky and #atdev community have some education work to do on the OAuth front, because some people seem to feel that OAuth is less secure than app passwords (see questions to Clearsky: why can't you just use app passwords like everyone else, why do I need to give you my real password etc.)
it's been a hot minute, but atex v0.10.0 is out now! oauth internals got a bit of a refactor, :telemetry events have been added to XRPC, identity resolution, OAuth flows, and service auth validation, and XRPC requests now have a custom User-Agent! #atproto #elixir
comet.sh/atex
tangled.orgDon’t fret, atproto OAuth is coming to Surf!
Surf
HI @velvetshadow.fr, we're working on it!