







I hope @dholms.at or someone else at @bsky.app considers this before it's too late and ACLs are baked into the protocol.
Authority as Possession: Permissioned Spaces Deserve Better Than ACLs
leaflet.pubApr 9, 2026 at 7:31 AM
OAuth for AT Protocol | Bluesky
We are very happy to release the initial specification of OAuth for AT Protocol! This is expected to be the primary authentication and authorization system between atproto client apps and PDS instances going forward, replacing the current flow using App Passwords and createSession over time.

ACLs don't
The ACL model is unable to make correct access decisions for interactions involving more than two principals, since required information is not retained across message sends. Though this deficiency has long been documented in the published literature, it is not widely understood. This logic error in the ACL model is exploited by both the clickjacking and Cross-Site Request Forgery attacks that affect many Web applications.



Building OAuth Authentication for Bluesky: A Complete Guide for Web and iOS Apps - Lost in Inference
How to implement secure, standards-compliant OAuth 2.1 + PKCE authentication for AT Protocol apps with separate web and mobile flows
tijs/atproto-oauth
Framework-agnostic OAuth integration for AT Protocol (Bluesky) applications
Proposal: OAuth Scopes · bluesky-social atproto · Discussion #3655
Note: a more complete proposal was published in July 2025: https://github.com/bluesky-social/proposals/tree/main/0011-auth-scopes We’re continuing work on rolling OAuth out to the atproto network. ...

Updated Auth Scopes Proposal · bluesky-social atproto · Discussion #4013
This is a discussion thread for the July 2025 Auth Scopes proposal
The AT Protocol | Bluesky
The AT Protocol (Authenticated Transfer Protocol, or atproto) is a standard for public conversation and an open-source framework for building social apps.

For our next Off Protocol Live, we're doing a permissioned data AMA with @dholms.at. Reply to this thread with your questions and tune into the livestream for more.
Off Protocol LIVE — Permissioned Data AMA
atmo.rsvp@bsky.app recently acquired the trademark for AT Protocol (and variants) to help protect the ecosystem. Here’s more about what that means. atproto.com/blog/at-protocol-trademark
AT Protocol Trademark
atproto.comI love to see when a *.host.bsky.network (mushroom PDS) user is informed in a nice, polite way about how the AT Protocol works and why it's awesome.
When @bsky.app pulls this kind of crap often, whilst also expecting the community to do the heavy-lifting in actually convincing people to try out the AT Protocol... it's really difficult to feel hopeful about the future of Bluesky and its constituents. I imagine many agree with this stance.
Rude1 Haunted Badness. ⁂
Bluesky’s statement deriding Threads users as “guinea pigs” is not representative of Blacksky Algorithms, the atproto ecosystem or the open social web more broadly. Communities form around communication networks. And communities should never be trolled for whatever tool helps them find each other.
Permission sets for bsky launched sometime early this year (and still have issues github.com/bluesky-social/atproto/issues…, github.com/bluesky-social/atproto/discus…). XRPC scopes were earlier, but as far as user communication goes it's not any better. Requesting one XRPC scope still looks scary for end users.