







PDS: review existing oauth scopes via connected apps list · Issue #4838 · bluesky-social/atproto
Scenario I want to stay on top of which apps are messing with what in my PDS. To do so, it's not enough to just make a granular Goldilocks decision once per app. (The more apps I use, the fewer...
The Case For Universal Login and "Off-Protocol" Services
OAuth API - Home
The Apigee OAuth API gives you a keychain for authenticating to Twitter, Salesforce, Salesforce Chatter, Facebook, Flickr, and Foursquare. Thousands of developers complain about the complexity of using OAuth. Now you can easily authenticate in one consistent way across several APIs and build apps faster.
Protecting web applications via Envoy OAuth2 filter
Putting our long-tenured investment teams on the line to earn the trust of institutional investors.
Oauth scopes vs record permissions
i hope this is an alright place to put this, but it was just a thought i had inspired by this tweet even with oauth scopes, i think that interoperability between applications is a tough problem because i have to fully trust every oauth client that i use with access to record namespaces. so if i have existing bluesky records, and then i want to use a different application which wants to be able to create and delete bluesky records, either i can’t use bluesky features in that application, or i ne...

Comforting Myths - Infrequently Noted
I've been hearing confusing reports of Apple's openness to collaboration on challenging APIs so often that either my priors are invalid, or something else is at work. To find out, I needed data.

Proposal: OAuth Scopes · bluesky-social atproto · Discussion #3655
Note: a more complete proposal was published in July 2025: https://github.com/bluesky-social/proposals/tree/main/0011-auth-scopes We’re continuing work on rolling OAuth out to the atproto network. ...
PACT: Anonymous Credentials for the Web – Mozilla Hacks - the Web developer blog
A deeper look at PACT: a new initiative to tackle the rising tide of CAPTCHAs on the web whilst keeping the web open and preserving user's privacy.

Implementing dynamic OAuth scoping so that people who don't want to give any Bluesky permissions can still log in to Streamplace. Do I gotta implement a totally separate metadata document? Currently we're at stream.place/oauth/upstream/client-metadat… but that has the scope inline... cc @thisismissem.social
Claude is inheriting a centralized app-centric bias here (which existing OAuth profiles may share) To wind up in a decentralized world where all "my data" lives on "my PDS" -- regardless of how many atproto apps I authorize to store stuff there for me (see 🧵) -- we should invert that paradigm
Paul Rohr
TL/DR = yes, it's a subtle conceptual shift: - from app-centric (apps control identity/data, delegating access to you at signin) - to identity-centric (you control identity/data, delegating access to apps at signin) Really looking forward to how the team evolves the OAuth UX to address this! /END
Standard Reader now publishes permission scopes! In human: When you log in we better explain what we're requesting and why The first one grants access to write data for our app, the second lets up create @standard.site subscriptions and likes for you
Once again looking at bring your own user-data storage options (for my malleable software experiment this time). What do people think are some user friendly options that don't require any OAuth apps to be created on the server? ie. no Dropbox, Google Drive, One Drive & other services like that.
note again this doesn't correspond to user traffic. e.g. some app might use typeahead.waow.tech 's endpoints for actor search in other places than login, and another app might have a bad oauth impl that forces users to login more still fun to look at tho!
standard-reader.app vs pckt · typeahead traffic
typeahead.waow.tech3) it still doesn't fully cover all use cases well or at all 4) bsky.app still didn't manage to implement OAuth at all Yes, we should all be moving to OAuth w/ scopes, that's the goal, but give people some slack, it's all still rather fresh, we'll get there… (yes, it's me, I'm those people)
The most annoying part of using these apps for professional conferences is signing up, linking with people, and losing those connections b/c you never use the app again. This seems like something AT protocol was made for. Anyone at @sifa.id or @semble.so interested in putting this together? 👀
Richard Ferro, MD MSc
Is there already a conference app on AT proto?