







Proposal: OAuth-based account creation · bluesky-social atproto · Discussion #4587
We recently added to the reference PDS (and underlying OAuth Provider) implementation support for Initiating User Registration via OpenID Connect 1.0, however, what I wasn't aware of when I add...
PDS: review existing oauth scopes via connected apps list · Issue #4838 · bluesky-social/atproto
Scenario I want to stay on top of which apps are messing with what in my PDS. To do so, it's not enough to just make a granular Goldilocks decision once per app. (The more apps I use, the fewer...
What is OAuth?
Wherein I [try to] answer a seemingly straightforward question: "WTF is OAuth, anyhow?"
OAuth Roadmap · bluesky-social atproto · Discussion #2656
OAuth is nigh! Protocol support has been a long time coming and we are pumped. It should greatly improve the user and developer experiences building secure apps and integrations on atproto. And cou...
Let's fix OAuth in MCP
Update: The changes described in this blog post have been incorporated into the 2025-06-18 version of the MCP spec!

your app can run its own pds - keith.is
if you’re building on atproto, you’ve probably reached for “sign in with bluesky” as your auth story. it works! the OAuth flow is fine. but every time a user shows up without a bluesky account, you have to send them to bluesky first, watch them get confused by a totally different brand, and hope they come back. that’s a weird seam in your own product.

🦫 alert! We published the second episode of "Teach the Web new Tricks", featuring native support for @atproto.com ! Learn more how we improve user agency and privacy at webbeef.org/atproto.html : - Native at:// protocol support. - Log in your PDS and forget OAuth ! - Authorize 3rd parties
Hey @surf.social the atproto early adopter / tech community can’t recommend you until you implement OAuth. This is a pretty big user security issue. Let us know if you need help or contract @thisismissem.social
im'bcmgs'im
surf.social looks amazing but idk about this login experience... i dont normally wanna put my password for one site into another site 🙃
there’s a reason why i added this informational box to the sign in flow for @anisota.net — i wanted to make it clearer that the user is redirected away from anisota and to their own account/PDS… and that anisota isn’t getting their password helps that anisota’s design is SO diff from the oauth page
Kuba Suder 🇵🇱🇺🇦
I think Bluesky and #atdev community have some education work to do on the OAuth front, because some people seem to feel that OAuth is less secure than app passwords (see questions to Clearsky: why can't you just use app passwords like everyone else, why do I need to give you my real password etc.)
I've been saying for nearly a year that getting the UX right for bsky's OAuth deployment is a major inflection point for reinforcing users mental models If we phrase things right, people will learn that this password UX controls access to my identity + slices of my atmosphere data (via my PDS)
Paul Rohr
Claude is inheriting a centralized app-centric bias here (which existing OAuth profiles may share) To wind up in a decentralized world where all "my data" lives on "my PDS" -- regardless of how many atproto apps I authorize to store stuff there for me (see 🧵) -- we should invert that paradigm
Don’t fret, atproto OAuth is coming to Surf!
Surf
HI @velvetshadow.fr, we're working on it!
3) it still doesn't fully cover all use cases well or at all 4) bsky.app still didn't manage to implement OAuth at all Yes, we should all be moving to OAuth w/ scopes, that's the goal, but give people some slack, it's all still rather fresh, we'll get there… (yes, it's me, I'm those people)
Claude is inheriting a centralized app-centric bias here (which existing OAuth profiles may share) To wind up in a decentralized world where all "my data" lives on "my PDS" -- regardless of how many atproto apps I authorize to store stuff there for me (see 🧵) -- we should invert that paradigm
Paul Rohr
TL/DR = yes, it's a subtle conceptual shift: - from app-centric (apps control identity/data, delegating access to you at signin) - to identity-centric (you control identity/data, delegating access to apps at signin) Really looking forward to how the team evolves the OAuth UX to address this! /END
what do u think chat? should bsky upstream this? :o reference pds oauth ui redesign. bonus: also includes updates to account management ui. check out the github for screenshots 👇👩🍳🙂↕️😯😵🫣🤗🫨😌☺️ github.com/abcbrookie/atproto/blob/brook…
reminder that you can always revoke oauth access at bsky.social/account (also a good place to check for apps you forgot you logged in to !)