







3) it still doesn't fully cover all use cases well or at all 4) bsky.app still didn't manage to implement OAuth at all Yes, we should all be moving to OAuth w/ scopes, that's the goal, but give people some slack, it's all still rather fresh, we'll get there… (yes, it's me, I'm those people)
Apr 13, 2026 at 4:26 PM
Building OAuth Authentication for Bluesky: A Complete Guide for Web and iOS Apps - Lost in Inference
How to implement secure, standards-compliant OAuth 2.1 + PKCE authentication for AT Protocol apps with separate web and mobile flows
Bluesky social oauth scope "Bad token scope"
I'm trying to build an app that integrates with bsky's OAuth and API. Using the below the document using the "Browser App" option. https://docs.bsky.app/docs/advanced-guides/oauth-client ...
PDS: review existing oauth scopes via connected apps list · Issue #4838 · bluesky-social/atproto
Scenario I want to stay on top of which apps are messing with what in my PDS. To do so, it's not enough to just make a granular Goldilocks decision once per app. (The more apps I use, the fewer...
How I Implemented OAuth for Bluesky in a Next.js App
OAuth is a standard, but every platform has its quirks. When Bluesky released their OAuth...

OAuth Client Implementation | Bluesky
This is a guide to implementing atproto OAuth clients "The Hard Way." Optimistically, most developers will have an SDK available for their programming language which supports OAuth, and they can simply refer to SDK documentation. This guide is intended for early adopters, SDK maintainers, or developers with more sophisticated OAuth needs. It is agnostic to whether developers are building clients to work the the app.bsky microblogging Lexicons, or implementing novel application Lexicons.

OAuth scopes (#3806) · bluesky-social/atproto@1899b1f
* style: prefix `id` and `uri` with `request` where applicable * Dynamically validate OAuth scopes * Allow configuring trusted OAuth clients * Improve client validation * Rework authorization t...
Oauth scopes vs record permissions
i hope this is an alright place to put this, but it was just a thought i had inspired by this tweet even with oauth scopes, i think that interoperability between applications is a tough problem because i have to fully trust every oauth client that i use with access to record namespaces. so if i have existing bluesky records, and then i want to use a different application which wants to be able to create and delete bluesky records, either i can’t use bluesky features in that application, or i ne...

Proposal: OAuth Scopes · bluesky-social atproto · Discussion #3655
Note: a more complete proposal was published in July 2025: https://github.com/bluesky-social/proposals/tree/main/0011-auth-scopes We’re continuing work on rolling OAuth out to the atproto network. ...
In 2026, @bsky.app is focused on what’s next for open social: bringing together users for conversations around live events, creator and platform monetization, and private state, giving users truly private data while preserving ownership and portability at the protocol level.
Bluesky isn’t just one app. It’s part of a much larger ecosystem, and your account is the key. Here are 7 useful apps you can log into with your @bsky.app account that you should know about.
7 Apps You Can Unlock With Your Bluesky Account
storm.leaflet.pubwhat do u think chat? should bsky upstream this? :o reference pds oauth ui redesign. bonus: also includes updates to account management ui. check out the github for screenshots 👇👩🍳🙂↕️😯😵🫣🤗🫨😌☺️ github.com/abcbrookie/atproto/blob/brook…
reminder that you can always revoke oauth access at bsky.social/account (also a good place to check for apps you forgot you logged in to !)
When @bsky.app pulls this kind of crap often, whilst also expecting the community to do the heavy-lifting in actually convincing people to try out the AT Protocol... it's really difficult to feel hopeful about the future of Bluesky and its constituents. I imagine many agree with this stance.
Rude1 Haunted Badness. ⁂
Bluesky’s statement deriding Threads users as “guinea pigs” is not representative of Blacksky Algorithms, the atproto ecosystem or the open social web more broadly. Communities form around communication networks. And communities should never be trolled for whatever tool helps them find each other.
also it is completely bonkers that @bsky.app requires you to select a "Hosting Provider" on login and i have to remember whatever @eurosky.social's address is. guys, if you want this decentralization thing to happen, it should not suck so much to use! the Bluesky app should just read it from my DID
reminder: the biggest atmosphere app in existence (bluesky) does not even have OAuth yet and has total access to your account scopes will come to @anisota.net, but it’s gonna take a bit longer & the lack of scopes is not due to forgetfulness or low quality… scopes didn’t exist when i made anisota
I've been saying for nearly a year that getting the UX right for bsky's OAuth deployment is a major inflection point for reinforcing users mental models If we phrase things right, people will learn that this password UX controls access to my identity + slices of my atmosphere data (via my PDS)
Paul Rohr
Claude is inheriting a centralized app-centric bias here (which existing OAuth profiles may share) To wind up in a decentralized world where all "my data" lives on "my PDS" -- regardless of how many atproto apps I authorize to store stuff there for me (see 🧵) -- we should invert that paradigm