







while we're here, here's how i wish permission sets were explained to me
atproto made simple: granular permissions
underreacted.leaflet.pubApr 13, 2026 at 8:22 PM
Early Permission Sets · bluesky-social atproto · Discussion #4437
Progress is coming along on "Permission Sets", as part of the atproto OAuth and permission system. As with other parts of the protocol, seeing how this functionality gets implemented for ...
Permission set (#4108) · bluesky-social/atproto@f9dc9aa
* Export constants and type assertion utilities * Add permission set support to oauth provider * improve permission set parsing * Rename `PermissionSet` to `ScopePermissions` * Improve performa...
Permissioned Data Diary 6: Boring Auth - Daniel's Leaflets
In which we resist the temptation to invent a clever authorization model & pick the boring one instead.
Permissioned Data Diary 5: What’s in a Name? - Daniel's Leaflets
In this permissioned data diary, we dive deep into the URI structure for permissioned data on atproto and use it to motivate a bunch of the larger design.
Permissioned Data Diary 5: What’s in a Name? - Daniel's Leaflets
In this permissioned data diary, we dive deep into the URI structure for permissioned data on atproto and use it to motivate a bunch of the larger design.
How to handle granular permissions | Authorization Resources | Google for Developers
Granular permissions give users more control over the specific data they share with apps, improving transparency, security, and trust.

Permissioned Data Diary 2: Buckets - Daniel's Leaflets
The second in a series of posts building up a solution to permissioned data on atproto. We introduce buckets: a new protocol primitive for creating a shared social context.
here it is folks! lots of details to still nail down, but this is roughly where our heads are at for the design of a permissioned data protocol give it a read and let me know your thoughts!
Permissioned Data Diary 4: The Big Picture
dholms.leaflet.pubwhy they’re bad? just ask claude. it ran into the same exact things i’ve ran into. until all of these are fixed imo its perfectly acceptable for developers to ignore permission sets. they’re just not baked until they’re understandable read this transcript: claude.ai/share/dbd3e30d-958d-4ac8-a3fc…
Claude
claude.aias a little pre-show surprise, here's an early draft of the permissioned data proposal! github.com/bluesky-social/proposals/pull…
Permissioned data by dholms · Pull Request #94 · bluesky-social/proposals
github.comAT Protocol Developers
Don't forget, @dholms.at is joining us for the livestream TOMORROW for a permissioned data AMA.
I really love how this handy widget lets you quickly browse through permission sets for various existing services Pro tip for lexicon designers: This is a great way to learn from peers -- @sifa.id, @beaconbits.app, etc -- who've done the work to decompose their permissions into useful subsets 😉
looking for feedback on the first pass of permissioned data protocol lexicons! hop in & let me know your thoughts! discourse.atprotocol.community/t/permissioned-data-pds-lexic…
Permissioned Data PDS Lexicons
discourse.atprotocol.communityas a little pre-show surprise, here's an early draft of the permissioned data proposal! github.com/bluesky-social/proposals/pull…
Permissioned data by dholms · Pull Request #94 · bluesky-social/proposals
github.comAT Protocol Developers
Don't forget, @dholms.at is joining us for the livestream TOMORROW for a permissioned data AMA.
@dholms.at motivated me to make a follow up post on Stratos, @transrights.northsky.social approach to permission data on ATproto! This one is a bit of a brief technical overview and as a nice bonus, I've made the code base public.
Stratos: Lets get Technical
chipnick.com