







The question came up today "When will Bluesky support 2FA for things like passkeys", etc besides email. I've talked about it a bit spread out, but thought I'd do a 🧵 on the lay of the land with auth and 2FA in the atmosphere
Felix Schneider
Regarding one question from today's atproto x npmx x svelte meetup: npmx.social already supports 2FA with email thanks to @pds.dad 🥳💐
Jul 15, 2026 at 10:10 PM
Progress on Auth Scopes Implementation (August 2025) · bluesky-social atproto · Discussion #4118
Since our last update on Auth Scopes, the Bluesky team has been hard at work adding support to our reference PDS implementation. Aspects of this work are starting to roll out in the production netw...
Securely authenticate with your Bluesky account using OAuth 2.0 with DPoP (Demonstrating Proof-of-Possession) tokens.
How I Implemented OAuth for Bluesky in a Next.js App
OAuth is a standard, but every platform has its quirks. When Bluesky released their OAuth...

Request For Comments: A secure contact import scheme for social networks | Bluesky
This article outlines plans for a future Bluesky feature \- it doesn’t exist yet\! By sharing our ideas early, we hope to solicit feedback from the community.

Building OAuth Authentication for Bluesky: A Complete Guide for Web and iOS Apps - Lost in Inference
How to implement secure, standards-compliant OAuth 2.1 + PKCE authentication for AT Protocol apps with separate web and mobile flows
Updated Auth Scopes Proposal · bluesky-social atproto · Discussion #4013
This is a discussion thread for the July 2025 Auth Scopes proposal
Bluesky SSH Authentication #2
Addressing the glaring omissions from yesterday’s proof of concept, such as the fact that you could sign in as any user, you couldn’t revoke access, all hosts had the same users, and there was no mapping between Bluesky handles and POSIX users, I have updated mtelvers/bluesky-ssh-key-extractor and newly published mtelvers/bluesky-collection.

Bluesky trust and safety is too important to be left to Bluesky
Bluesky is open about almost everything, except setting and enforcing their community guidelines. They have an opportunity to lead the Internet forward, but they need to start now.


Verified Account Tracker (@verified.evil.gay)
⚠️ ⚠️ ⚠️ !!! >>> NOT AFFILIATED WITH BLUESKY <<< !!! ⚠️ ⚠️ ⚠️ A bot tracking newly verified accounts on Bluesky. Check out the lists tab for full lists on verified accounts. ran by: @mmatt.net https://github.com/mmattbtw/bsky-verified-account-tracker
This Website is Hosted on Bluesky
Well, not this one. But this one is! How? Let’s take a closer look at Bluesky and the AT Protocol that underpins it. Note: I communicated with the Bluesky team prior to the publishing of this post. While the functionality described is not the intended use of the application, it is known behavior and does not constitue a vulnerability disclosure process. My main motivation for reaching out to them was because I like the folks and don’t want to make their lives harder.

Bluesky isn’t just one app. It’s part of a much larger ecosystem, and your account is the key. Here are 7 useful apps you can log into with your @bsky.app account that you should know about.
7 Apps You Can Unlock With Your Bluesky Account
storm.leaflet.pubWhen @bsky.app pulls this kind of crap often, whilst also expecting the community to do the heavy-lifting in actually convincing people to try out the AT Protocol... it's really difficult to feel hopeful about the future of Bluesky and its constituents. I imagine many agree with this stance.
Rude1 Haunted Badness. ⁂
Bluesky’s statement deriding Threads users as “guinea pigs” is not representative of Blacksky Algorithms, the atproto ecosystem or the open social web more broadly. Communities form around communication networks. And communities should never be trolled for whatever tool helps them find each other.
It's really cool that people are now using Bluesky not only from servers they host themselves, but servers they *wrote* themselves (or someone else here did), adding features the standard one doesn't have ❤️ Like, I now have 2FA again on my PDS because @baileytownsend.dev just went and built it
Matt Kane
Cirrus PDS now support passkey auth. It was a bit of a puzzle adding it to a tool where where the admin is all CLI, but I'm really pleased with the flow I came up with. Give it a go! github.com/ascorbic/cirrus If you don't know what Cirrus is, it's a really easy way to host your own Bluesky data
You can sign up for @inspo.land with your bluesky account! under the hood it creates a new private PDS using bsky for auth still a bit finicky sometimes, so lmk if you run into any issues!
I've been saying for nearly a year that getting the UX right for bsky's OAuth deployment is a major inflection point for reinforcing users mental models If we phrase things right, people will learn that this password UX controls access to my identity + slices of my atmosphere data (via my PDS)
Paul Rohr
Claude is inheriting a centralized app-centric bias here (which existing OAuth profiles may share) To wind up in a decentralized world where all "my data" lives on "my PDS" -- regardless of how many atproto apps I authorize to store stuff there for me (see 🧵) -- we should invert that paradigm