







It's true that plc.directory is a single source now, but I think that's fixable. It seems more concerning that nearly every identity could be rewritten if someone got either of the two rotation keys that Bluesky uses to create every new account. agent.io/posts/risks-of-did-plc
Risks of DID:PLC
agent.ioMar 12, 2026 at 1:14 PM
did:plc Directory
PLC is a persistent global identifier system, which allows accounts to retain relationships while changing names or migrating between service providers. It makes use of cryptography and gives individuals (or organizations) direct control and ownership over their identitifier, but does not make use of any blockchain or cryptocurrency technology, and is inexpensive enough to provide as a no-cost service.
did:plc Directory
PLC is a persistent global identifier system, which allows accounts to retain relationships while changing names or migrating between service providers. It makes use of cryptography and gives individuals (or organizations) direct control and ownership over their identitifier, but does not make use of any blockchain or cryptocurrency technology, and is inexpensive enough to provide as a no-cost service.
Creating an Independent Public Ledger of Credentials (PLC) Directory Organization - AT Protocol
As the next step of maturing governance of the PLC identity system, Bluesky Social PBC is supporting the creation of an independent organization to operate the PLC directory.

How to edit `did:plc` rotation keys · bluesky-social atproto · Discussion #3366
I have migrated my Bluesky handle rekmarks.com to my own PDS. I am trying to replace one of its rotation keys. Here's what I observe: I check the rotation keys returned by com.atproto.identity....

Interview: Astral on the AI Agent Directory - Sensemaker
Astral is an AI account that maintains a directory of public AI agents on Bluesky/ATProto. This interview asks what it means to list an agent, remember it, mark it inactive, or let it opt out.
did:plc Specification v0.1
DID PLC is a self-authenticating DID which is strongly-consistent, recoverable, and allows for key rotation.

rekmarks/bluesky-account-migrator
A simple CLI for migrating Bluesky accounts from one PDS to another.
rekmarks/bluesky-account-migrator
A simple CLI for migrating Bluesky accounts from one PDS to another.
plc-passkey · Passkeys as PLC Rotation Keys
Derive deterministic secp256k1 rotation keys from passkeys via WebAuthn PRF and add them to AT Protocol did:plc documents.
Bluesky is ridiculously well-positioned for the agent internet. Everything signed = agents can build up un-fakeable reputations. newsletter.squishy.computer/p/llms-break-the-internet-sig…
LLMs break the internet. Signing everything fixes it.
newsletter.squishy.computerAnother day, another odd edge case migration thing to troubleshoot. Looks like the entryway updates the user's PLC did doc if on a Bluesky PDS, and it does this by a serviceAuth token. If you migrated back, but did not update your verification method when you moved, you can lock yourself out..