







🚨 Docs News!! you all asked for it, so I did a medium-sized refactor of the Auth section of the atproto docs: atproto.com/guides/auth I appreciated all the little pushes here as well as contributions from @danabra.mov and @zzstoatzz.io — much happier with the flow here now and hope you will be too!
Auth - AT Protocol Docs - AT Protocol
atproto.comApr 16, 2026 at 3:39 PM
OAuth Improvements - AT Protocol
We've been making improvements to the end-user and developer experiences with atproto OAuth.

OAuth for ATProto Apps Part 2: Mobile Implementation - Lost in Inference
Part 2 of a 2-part series on implementing OAuth authentication for ATProto (Bluesky) applications.
Building OAuth Authentication for ATProto apps: Part 1, the web use-case - Building on atproto
In this follow-up OAuth implementation guide I dive a bit deeper into the actual implementation details of building authentication for your web or mobile app that builds on top of ATProto.

sparrowtek.com/atproto-auth-proxy
Stateless auth proxy that converts AT Protocol native apps from public to confidential OAuth clients. Deploy once, get 180-day refresh tokens instead of 24-hour ones.
sparrowtek.com/atproto-auth-proxy
Stateless auth proxy that converts AT Protocol native apps from public to confidential OAuth clients. Deploy once, get 180-day refresh tokens instead of 24-hour ones.
index.html · by atprotofans.com
An browser-side ATProtocol OAuth application with no dependencies that verifies supporters
Service Auth | Bluesky
There are currently two "types" of auth supported in the atproto network: client-server auth and service-to-service auth.

Beyond the Statusphere: Part 2, ATProto OAuth, the TLDR - Hitchhiker's Guide to the Atmosphere
Gain a working knowledge of ATProto OAuth and feel confident implementing it in your projects.
j4ckxyz/atproto-oauth-reference
Contribute to j4ckxyz/atproto-oauth-reference development by creating an account on GitHub.
ATProto Integration - poke_around
OAuth, PDS sync, custom lexicons, and user bookmarking via the AT Protocol.

Pleased to announce that an Authenticated Transfer Protocol (ATP) working group has been created at the IETF! Grateful to everybody who participated in the BoF and chartering process. Details on next steps and how to get involved inside. atproto.com/blog/kicking-off-the-atp-work…
Kicking off the ATP Working Group at the IETF - AT Protocol
atproto.comso uhh... I needed a thing and it is here - tangled.org/sparrowtek.com/atproto-auth-p…
sparrowtek.com/atproto-auth-proxy
tangled.orgHey @surf.social the atproto early adopter / tech community can’t recommend you until you implement OAuth. This is a pretty big user security issue. Let us know if you need help or contract @thisismissem.social
im'bcmgs'im
surf.social looks amazing but idk about this login experience... i dont normally wanna put my password for one site into another site 🙃
Another OIDC gateway approach for using your atproto account to login to many different things tangled.org/bkb.arcnode.xyz/atauth Nice work @bkb.arcnode.xyz!
bkb
Giving @tangled.org a try. Updates to the atauth OIDC gateway are live. Passkey login for all apps -- Sign in with biometrics or a security key on every app 8 security fixes enforced session expiry Multi-arch Docker on GHCR One docker pull for amd64 and arm64 (Pi, Apple Silicon)