







This is awesome. I made a PR last week to add better support and display for permission-sets to the OAuth consent screen for @tranquil.farm. Now every time I log in to my Atmosphere account, I can actually see my fingerprints on Tranquil. 😍 #atproto
Jul 26, 2026 at 3:18 PM
OAuth Improvements - AT Protocol
We've been making improvements to the end-user and developer experiences with atproto OAuth.

Crafting a Better Atmospheric Auth Flow
Crafting a Better Atmospheric Auth Flow For the sake of your users ! By @brookie.blog
Crafting a Better Atmospheric Auth Flow
Crafting a Better Atmospheric Auth Flow For the sake of your users ! By @brookie.blog
Verifire — verify an atmosphere account (atproto handle) without login
Issue a one-time code, the user creates any record in their atproto repo (a Bluesky post, a Blacksky post, a custom record), Verifire spots it on the firehose and hands you back the DID and handle. No OAuth, no PDS calls.
Don’t fret, atproto OAuth is coming to Surf!
Surf
HI @velvetshadow.fr, we're working on it!
This is awesome. I made a PR last week to add better support and display for permission-sets to the OAuth consent screen for @tranquil.farm. Now every time I log in to my Atmosphere account, I can actually see my fingerprints on Tranquil. 😍 #atproto
PDS folks! Working on a redesign of the authentication and dashboard screens for the reference PDS, bringing in a proper component library and consistent patterns across the UI. One notable change: customizable light/dark backgrounds on the auth screens. Let us know what you think! #atproto
there’s a reason why i added this informational box to the sign in flow for @anisota.net — i wanted to make it clearer that the user is redirected away from anisota and to their own account/PDS… and that anisota isn’t getting their password helps that anisota’s design is SO diff from the oauth page
Kuba Suder 🇵🇱🇺🇦
I think Bluesky and #atdev community have some education work to do on the OAuth front, because some people seem to feel that OAuth is less secure than app passwords (see questions to Clearsky: why can't you just use app passwords like everyone else, why do I need to give you my real password etc.)
I've been saying for nearly a year that getting the UX right for bsky's OAuth deployment is a major inflection point for reinforcing users mental models If we phrase things right, people will learn that this password UX controls access to my identity + slices of my atmosphere data (via my PDS)
Paul Rohr
Claude is inheriting a centralized app-centric bias here (which existing OAuth profiles may share) To wind up in a decentralized world where all "my data" lives on "my PDS" -- regardless of how many atproto apps I authorize to store stuff there for me (see 🧵) -- we should invert that paradigm
Halfway through finishing my @astro.build @standard.site plugin to post my blog posts into #atproto and also pull my @leaflet.pub posts out and sync them! @pfrazee.com I hear you're building a full renderer!
Hey @surf.social the atproto early adopter / tech community can’t recommend you until you implement OAuth. This is a pretty big user security issue. Let us know if you need help or contract @thisismissem.social
im'bcmgs'im
surf.social looks amazing but idk about this login experience... i dont normally wanna put my password for one site into another site 🙃
🦫 alert! We published the second episode of "Teach the Web new Tricks", featuring native support for @atproto.com ! Learn more how we improve user agency and privacy at webbeef.org/atproto.html : - Native at:// protocol support. - Log in your PDS and forget OAuth ! - Authorize 3rd parties
dame (@dame.is)

OAuth Patterns - AT Protocol Docs - AT Protocol
atproto made simple: granular permissions - underreacted
graze-social/aip
Bluesky social oauth scope "Bad token scope"

oAuthLoginwithBsky.md