







I need folks to understand that there are also a LOT of users who prefer app passwords bc OAuth makes them feel uncomfortable.
im'bcmgs'im
surf.social looks amazing but idk about this login experience... i dont normally wanna put my password for one site into another site 🙃
Apr 3, 2026 at 2:17 PM
What is OAuth?
Wherein I [try to] answer a seemingly straightforward question: "WTF is OAuth, anyhow?"
OAuth API - Home
The Apigee OAuth API gives you a keychain for authenticating to Twitter, Salesforce, Salesforce Chatter, Facebook, Flickr, and Foursquare. Thousands of developers complain about the complexity of using OAuth. Now you can easily authenticate in one consistent way across several APIs and build apps faster.
The OAuth mechanism and its most common flows
Every single time when you want to sign in to an application and you click on “Login with Google”, you are starting a protocol called…



Building OAuth Authentication for Bluesky: A Complete Guide for Web and iOS Apps - Lost in Inference
How to implement secure, standards-compliant OAuth 2.1 + PKCE authentication for AT Protocol apps with separate web and mobile flows
What login method do you consider most privacy-respecting?
I've been thinking about authentication methods and the privacy and security trade-offs for a project I'm working on. I've already ruled out OAuth…
Building OAuth Authentication for ATProto apps: Part 1, the web use-case - Building on atproto
In this follow-up OAuth implementation guide I dive a bit deeper into the actual implementation details of building authentication for your web or mobile app that builds on top of ATProto.
Protecting web applications via Envoy OAuth2 filter
Putting our long-tenured investment teams on the line to earn the trust of institutional investors.
I've been saying for nearly a year that getting the UX right for bsky's OAuth deployment is a major inflection point for reinforcing users mental models If we phrase things right, people will learn that this password UX controls access to my identity + slices of my atmosphere data (via my PDS)
Paul Rohr
Claude is inheriting a centralized app-centric bias here (which existing OAuth profiles may share) To wind up in a decentralized world where all "my data" lives on "my PDS" -- regardless of how many atproto apps I authorize to store stuff there for me (see 🧵) -- we should invert that paradigm
Claude is inheriting a centralized app-centric bias here (which existing OAuth profiles may share) To wind up in a decentralized world where all "my data" lives on "my PDS" -- regardless of how many atproto apps I authorize to store stuff there for me (see 🧵) -- we should invert that paradigm
Paul Rohr
TL/DR = yes, it's a subtle conceptual shift: - from app-centric (apps control identity/data, delegating access to you at signin) - to identity-centric (you control identity/data, delegating access to apps at signin) Really looking forward to how the team evolves the OAuth UX to address this! /END
So this is one of the cool things about apps in the Atmosphere. They have to declare what stuff in your account they're going to touch.
ATStore
You find a cool new Atmosphere app. You click sign in. And then... a wall of permission requests you didn't expect. 😬 ATStore fixes that. Every app listing now has a "scopes" badge, tap it to see what the app will request before you ever log in. ⚠️ Requesting dangerous scopes? Get warned.
agreed. "𝕃𝕖𝕥’𝕤 𝕟𝕠𝕣𝕞𝕒𝕝𝕚𝕫𝕖 𝕤𝕒𝕪𝕚𝕟𝕘 𝕨𝕙𝕠 𝕥𝕙𝕖 𝕙𝕦𝕞𝕒𝕟𝕤 𝕒𝕣𝕖 𝕡𝕝𝕖𝕒𝕤𝕖." i understand the desire for privacy, but building trust for people to use a thing, or even just login to a thing should clearly indicate who built a thing #atdev most peolpe won't dig as hard as i do to determine who a dev of a thing is
Boris
@atmosphere.tickets you don’t appear to have DMs turned on and no indication of who you are. Following that to @atmosphere.money and the about page, also no people mentioned. Let’s normalize saying who the humans are please.
3) it still doesn't fully cover all use cases well or at all 4) bsky.app still didn't manage to implement OAuth at all Yes, we should all be moving to OAuth w/ scopes, that's the goal, but give people some slack, it's all still rather fresh, we'll get there… (yes, it's me, I'm those people)
dame (@dame.is)

OAuth Patterns - AT Protocol Docs - AT Protocol
atproto made simple: granular permissions - underreacted
graze-social/aip
Bluesky social oauth scope "Bad token scope"

oAuthLoginwithBsky.md