







Does OpenID need to be hard?
Prompted by posts by Randy Reddig and Tony Stubblebine and a conversation with Elliott Kember, I wanted to address, yet again, the big fat stinking elephant in the room: OpenID usability and the pa…

ATLogin - OIDC for ATProto/Bluesky
ATLogin lets you use your ATProto/Bluesky identity to log in to any application that supports OIDC.
ATLogin - OIDC for ATProto/Bluesky
ATLogin lets you use your ATProto/Bluesky identity to log in to any application that supports OIDC.

@atproto/oauth-provider - AT Protocol
OAuth 2.0 and OpenID Connect authorization server for AT Protocol
Your identity isn't your username
Your handle is a label; your identity is a key you own. atproto splits who you are from what you're called, so you can rename freely, prove who you are with a domain you control, and carry one identity across the apps you use. Part of 'Apps as Views, Not Vaults': the things you make are yours; apps are just the viewers.

Add openid4vp: as a safelisted scheme for protocol registration handling · Issue #11552 · whatwg/html
What problem are you trying to solve? In the context of digital wallets, the OpenID for Verifiable Presentations (OID4VP) 1.0 specification defines a new URI scheme, openid4vp:. The openid4vp: sche...
So many people do not get this. Atproto identity is the closest thing to original-flavor OpenID that has been done in years. It's not OpenID (it has problems OpenID didn't and solves problems OpenID had), but it's very much in that spirit.
hailey
i guess in a way this is the most widely used one, but also one that is severely underused in other ways. definitely identity. i've long been of the opinion that there are obviously cool things that come from public data and all the public pieces of the proto, but identity is higher impact.
Sep 16, 2026 at 8:51 PM
this is kinda another reason im starting to think more and more that there would be worth in splitting atprotos identity layer out as its own spec and standard. building up handles and oauth around a DID makes for a really flexible cross platform (and potentially cross ecosystem) identity system
Nelind
i kinda hate how atproto adopting DIDs has made people intrinsically associate DIDs with atproto ... it makes some people see me as some annoying bitch trying to shove atproto into places it obviously doesnt belong in when i suggest using DIDs as user identifiers for other systems
Another OIDC gateway approach for using your atproto account to login to many different things tangled.org/bkb.arcnode.xyz/atauth Nice work @bkb.arcnode.xyz!
bkb
Giving @tangled.org a try. Updates to the atauth OIDC gateway are live. Passkey login for all apps -- Sign in with biometrics or a security key on every app 8 security fixes enforced session expiry Multi-arch Docker on GHCR One docker pull for amd64 and arm64 (Pi, Apple Silicon)
Once you experience shared lexicons and the benefits of a single portable identity, it feels like a new open network. But the most important part is that it practically works as an extension of the web. We can add social features to our websites without even mentioning atproto. Frictionless adoption
P(aul) Frazee
The Atmosphere is a new open network. The features: - Your account works on all atmosphere apps - You can switch to a new provider with no fuss - Easy to make your own apps on it - Works great with personal websites And, Bluesky is an atmosphere app.
If WSocial sold people on the idea that everyone they would interact with is ID-verified, then indeed, every single open ATProto community would act as a back door of sorts. The only way for them to deliver would be to de-federate entirely. And it's always a bad idea to bet against openness.
Wimster9030 🇪🇺 🇧🇪
I know, Daniel, but that's not the way WSocial "sold" it to us. We could only access trough ID-verification so we know for 100% they are EU and a "real person". That was the whole point. So we went trough that process, but now it seems that the backdoor are the other ATProt platforms to get in too.
I built a translator between Atproto's OAuth and OIDC, so apps like @tailscale.com can use your Bluesky identity. It includes a whitelist so you can invite people directly using their DID!
Decentralised Identity 🤝 Mesh Networking
thinking-with-portals.leaflet.pub