







Not even low-key, Access-Control-Allow-Origin: '*' everywhere is one of the best things that atproto has done. (I'm reasonably excited about this, in part because I've been waiting since shortly after it was proposed and first implemented. Here's a moan from 2010: x.com/blaine/status/13206867161?s=2…)
Mar 1, 2026 at 10:17 PM
atproto made simple: granular permissions - underreacted
atproto made simple: granular permissions - underreacted
Early Permission Sets · bluesky-social atproto · Discussion #4437
Progress is coming along on "Permission Sets", as part of the atproto OAuth and permission system. As with other parts of the protocol, seeing how this functionality gets implemented for ...
The Atproto Spaces Alpha is Live - AT Protocol
Atproto Spaces, formerly known as “the permissioned data protocol,” is a new extension to atproto that enables non-public data. The alpha is now officially open. Here’s how to develop with it and what to expect as we work towards the full release.

The Atproto Spaces Alpha is Live - AT Protocol
Atproto Spaces, formerly known as “the permissioned data protocol,” is a new extension to atproto that enables non-public data. The alpha is now officially open. Here’s how to develop with it and what to expect as we work towards the full release.

The Atproto Spaces Alpha is Live - AT Protocol
Atproto Spaces, formerly known as “the permissioned data protocol,” is a new extension to atproto that enables non-public data. The alpha is now officially open. Here’s how to develop with it and what to expect as we work towards the full release.

OAuth Roadmap · bluesky-social atproto · Discussion #2656
OAuth is nigh! Protocol support has been a long time coming and we are pumped. It should greatly improve the user and developer experiences building secure apps and integrations on atproto. And cou...
OAuth for ATProto Apps Part 2: Mobile Implementation - Lost in Inference
Part 2 of a 2-part series on implementing OAuth authentication for ATProto (Bluesky) applications.
index.html · by atprotofans.com
An browser-side ATProtocol OAuth application with no dependencies that verifies supporters

OAuth Improvements - AT Protocol
We've been making improvements to the end-user and developer experiences with atproto OAuth.

@tynanpurdy.com asked for this feature and I like it: every atproto app should support AT-URIs as top level routes, @pds.ls-style. Makes it super easy to integrate. So this would be an argument for e.g.: `https://bsky.app/at://did:plc:rbvrr34edl5ddpuwcubjiost/app.bsky.feed.post/3micfxauzu22c`
Support top-level AT-URI resolution · Issue #1012 · streamplace/streamplace
github.comBeen thinking about how we could support access-controlled blobs in ATProtocol. Right now, all blobs are public - anyone can fetch them with a CID. But what if we could gate them? #atproto #atdev 🧵
private_blobs.md
gist.github.comCompose | Taproot
Compose | Taproot

ATScience Ecosystem Map

Bluesky Protocol Services

Explore

AnyPub