







🧵 I've been wracking my brain around ATProto onboarding. Why do all ATProto apps make you create a new account before you can do anything interesting? Why don't we let people start with an email address or phone #? Then claim your identity if/when the need actually arises.
Jun 15, 2026 at 3:04 PM
Your identity isn't your username
Your handle is a label; your identity is a key you own. atproto splits who you are from what you're called, so you can rename freely, prove who you are with a domain you control, and carry one identity across the apps you use. Part of 'Apps as Views, Not Vaults': the things you make are yours; apps are just the viewers.

@me - explore your atproto identity
see your atmosphere account — one account, all your apps and data



Who Actually Owns Your ATProto Identity? Hint: It's Probably Not You
ATProto gives your PDS operator full control of your signing and rotation keys, letting them impersonate you across every app in the ecosystem or kill

My recollection of this is that even if you just pop a new ATProto account into existence and start spitting out `app.bsky.feed.post` records, they don't show up unless you actually go through a Bluesky onboarding & agreeing to ToS, so they should have an email for you through that process.
So this is one of the cool things about apps in the Atmosphere. They have to declare what stuff in your account they're going to touch.
ATStore
You find a cool new Atmosphere app. You click sign in. And then... a wall of permission requests you didn't expect. 😬 ATStore fixes that. Every app listing now has a "scopes" badge, tap it to see what the app will request before you ever log in. ⚠️ Requesting dangerous scopes? Get warned.
this is kinda another reason im starting to think more and more that there would be worth in splitting atprotos identity layer out as its own spec and standard. building up handles and oauth around a DID makes for a really flexible cross platform (and potentially cross ecosystem) identity system
Nelind
i kinda hate how atproto adopting DIDs has made people intrinsically associate DIDs with atproto ... it makes some people see me as some annoying bitch trying to shove atproto into places it obviously doesnt belong in when i suggest using DIDs as user identifiers for other systems