







note again this doesn't correspond to user traffic. e.g. some app might use typeahead.waow.tech 's endpoints for actor search in other places than login, and another app might have a bad oauth impl that forces users to login more still fun to look at tho!
standard-reader.app vs pckt · typeahead traffic
typeahead.waow.techJul 30, 2026 at 8:34 PM
app.bsky.actor.searchActorsTypeahead | Bluesky
*This endpoint is part of the Bluesky application Lexicon APIs (`app.bsky.*`). Public endpoints which don't require authentication can be made directly against the public Bluesky AppView API: https://public.api.bsky.app. Authenticated requests are usually made to the user's PDS, with automatic service proxying. Authenticated requests can be used for both public and non-public endpoints.*

The OAuth mechanism and its most common flows
Every single time when you want to sign in to an application and you click on “Login with Google”, you are starting a protocol called…

app.bsky.actor.getProfile | Bluesky
*This endpoint is part of the Bluesky application Lexicon APIs (`app.bsky.*`). Public endpoints which don't require authentication can be made directly against the public Bluesky AppView API: https://public.api.bsky.app. Authenticated requests are usually proxied via the user's PDS, using service proxy headers. Authenticated requests can be used for both public and non-public endpoints.*

Protecting web applications via Envoy OAuth2 filter
Putting our long-tenured investment teams on the line to earn the trust of institutional investors.
Atmospheric Login Page
The UX decisions behind my Atmosphere apps login pages — saved handles, handle autocomplete, and a 'create account' guardrail that slows people down on purpose.
Introduction - What is BrowserGate?
Linkedin is searching your computer Every time you visit linkedin.com, a JavaScript program embedded in the page scans your browser for installed Chrome extensions. The program runs silently, without any visible indicator to the user. It does not ask for consent. It does not disclose what it is doing. It reports the results to LinkedIn’s servers. This is not a one-time check. The scan runs on every page load, for every visitor.
PDS: review existing oauth scopes via connected apps list · Issue #4838 · bluesky-social/atproto
Scenario I want to stay on top of which apps are messing with what in my PDS. To do so, it's not enough to just make a granular Goldilocks decision once per app. (The more apps I use, the fewer...
OAuth Roadmap · bluesky-social atproto · Discussion #2656
OAuth is nigh! Protocol support has been a long time coming and we are pumped. It should greatly improve the user and developer experiences building secure apps and integrations on atproto. And cou...
OAuth API - Home
The Apigee OAuth API gives you a keychain for authenticating to Twitter, Salesforce, Salesforce Chatter, Facebook, Flickr, and Foursquare. Thousands of developers complain about the complexity of using OAuth. Now you can easily authenticate in one consistent way across several APIs and build apps faster.
Document: requestStorageAccess() method - Web APIs | MDN
The requestStorageAccess() method of the Document interface allows content loaded in a third-party context (i.e., embedded in an <iframe>) to request access to third-party cookies and unpartitioned state. This is relevant to user agents that, by default, block access to third-party, unpartitioned cookies to improve privacy (e.g., to prevent tracking), and is part of the Storage Access API.

AT Explore
Explore and discover AT Protocol data with our fast, user-friendly browser. Search posts, profiles, and feeds across the decentralized social web — including apps like Bluesky.
Everyone knows your location
How I tracked myself down using leaked location data in the in-app ads, and what I found along the way.
