







this is kinda another reason im starting to think more and more that there would be worth in splitting atprotos identity layer out as its own spec and standard. building up handles and oauth around a DID makes for a really flexible cross platform (and potentially cross ecosystem) identity system
Nelind
i kinda hate how atproto adopting DIDs has made people intrinsically associate DIDs with atproto ... it makes some people see me as some annoying bitch trying to shove atproto into places it obviously doesnt belong in when i suggest using DIDs as user identifiers for other systems
Mar 14, 2026 at 6:40 PM
OAuth Improvements - AT Protocol
We've been making improvements to the end-user and developer experiences with atproto OAuth.

ATLogin - OIDC for ATProto/Bluesky
ATLogin lets you use your ATProto/Bluesky identity to log in to any application that supports OIDC.
ATLogin - OIDC for ATProto/Bluesky
ATLogin lets you use your ATProto/Bluesky identity to log in to any application that supports OIDC.
OAuth for AT Protocol | Bluesky
We are very happy to release the initial specification of OAuth for AT Protocol! This is expected to be the primary authentication and authorization system between atproto client apps and PDS instances going forward, replacing the current flow using App Passwords and createSession over time.

OAuth for ATProto Apps Part 2: Mobile Implementation - Lost in Inference
Part 2 of a 2-part series on implementing OAuth authentication for ATProto (Bluesky) applications.
Who Actually Owns Your ATProto Identity? Hint: It's Probably Not You
ATProto gives your PDS operator full control of your signing and rotation keys, letting them impersonate you across every app in the ecosystem or kill

Building OAuth Authentication for ATProto apps: Part 1, the web use-case - Building on atproto
In this follow-up OAuth implementation guide I dive a bit deeper into the actual implementation details of building authentication for your web or mobile app that builds on top of ATProto.
@atproto/oauth-provider - AT Protocol
OAuth 2.0 and OpenID Connect authorization server for AT Protocol
tijs/atproto-oauth
Framework-agnostic OAuth integration for AT Protocol (Bluesky) applications
Once you experience shared lexicons and the benefits of a single portable identity, it feels like a new open network. But the most important part is that it practically works as an extension of the web. We can add social features to our websites without even mentioning atproto. Frictionless adoption
Paul Frazee
The Atmosphere is a new open network. The features: - Your account works on all atmosphere apps - You can switch to a new provider with no fuss - Easy to make your own apps on it - Works great with personal websites And, Bluesky is an atmosphere app.
the single most important part of atproto is the PDS as a user-controlled auth and storage layer to which clients can connect directly. death to appviews
Authenticated Transfer Enables Orchestration - nekomimi
blog.nekomimi.petnow updated my atproto oauth reference from last year! github.com/j4ckxyz/atproto-oauth-referen… - explains why to avoid `transition:generic` AND a skills file for your coding agent!!! github.com/j4ckxyz/atproto-oauth-referen… no reason to not have #atproto oauth anymore!
GitHub - j4ckxyz/atproto-oauth-reference
github.com@danabra.mov do you think it makes sense to frame atproto as providing a data and identity layer to the web, or as aiming to improve the web? I never want to overstep (see crypto claiming web3) but atproto is extremely web-brained like you said, and the web is where a lot of the utility shines
two things can be true 1. `transition:generic` is too broad of scope for most atproto apps and users should be aware 2. `transition:generic` is pretty much all we got as atproto devs while more granular oauth scopes are being developed and users are fear mongering too hard too early rn
e(Ag)le 🦅
Clearsky has updated to require authentication when viewing who blocks a user, and the permission scope it's asking for via bsky's oauth is...absolutely wild. Way, way, way too many permission grants there, folks.