







Permission sets for bsky launched sometime early this year (and still have issues github.com/bluesky-social/atproto/issues…, github.com/bluesky-social/atproto/discus…). XRPC scopes were earlier, but as far as user communication goes it's not any better. Requesting one XRPC scope still looks scary for end users.
Apr 13, 2026 at 4:23 PM
Progress on Auth Scopes Implementation (August 2025) · bluesky-social atproto · Discussion #4118
Since our last update on Auth Scopes, the Bluesky team has been hard at work adding support to our reference PDS implementation. Aspects of this work are starting to roll out in the production netw...
Bluesky social oauth scope "Bad token scope"
I'm trying to build an app that integrates with bsky's OAuth and API. Using the below the document using the "Browser App" option. https://docs.bsky.app/docs/advanced-guides/oauth-client ...
Bluesky permission sets require inconsistent aud parameter · Issue #4850 · bluesky-social/atproto
Describe the bug In trying to rewrite sill.social to use granular permission sets, I've found that app.bsky.authViewAll does not allow access to app.bsky.feed.getFeedGenerator, app.bsky.graph.g...
Appendix:Xanadu - AT Protocol Paper Errata and Details
A description of known problems in Bluesky PBC's paper, "Bluesky and the AT Protocol: Usable Decentralized Social Media", as well as notes on terminology changes and how Bluesky's implementation differs from that described in the paper.
app.bsky.notification.getPreferences | Bluesky
*This endpoint is part of the Bluesky application Lexicon APIs (`app.bsky.*`). Public endpoints which don't require authentication can be made directly against the public Bluesky AppView API: https://public.api.bsky.app. Authenticated requests are usually made to the user's PDS, with automatic service proxying. Authenticated requests can be used for both public and non-public endpoints.*

proposals/0016-permissioned-data at main · bluesky-social/proposals
Bluesky proposal discussions. Contribute to bluesky-social/proposals development by creating an account on GitHub.
app.bsky.actor.getProfile | Bluesky
*This endpoint is part of the Bluesky application Lexicon APIs (`app.bsky.*`). Public endpoints which don't require authentication can be made directly against the public Bluesky AppView API: https://public.api.bsky.app. Authenticated requests are usually proxied via the user's PDS, using service proxy headers. Authenticated requests can be used for both public and non-public endpoints.*

app.bsky.actor.searchActorsTypeahead | Bluesky
*This endpoint is part of the Bluesky application Lexicon APIs (`app.bsky.*`). Public endpoints which don't require authentication can be made directly against the public Bluesky AppView API: https://public.api.bsky.app. Authenticated requests are usually made to the user's PDS, with automatic service proxying. Authenticated requests can be used for both public and non-public endpoints.*

proposals/0016-permissioned-data/README.md at main · bluesky-social/proposals
Bluesky proposal discussions. Contribute to bluesky-social/proposals development by creating an account on GitHub.
When @bsky.app pulls this kind of crap often, whilst also expecting the community to do the heavy-lifting in actually convincing people to try out the AT Protocol... it's really difficult to feel hopeful about the future of Bluesky and its constituents. I imagine many agree with this stance.
Rude1 Haunted Badness. ⁂
Bluesky’s statement deriding Threads users as “guinea pigs” is not representative of Blacksky Algorithms, the atproto ecosystem or the open social web more broadly. Communities form around communication networks. And communities should never be trolled for whatever tool helps them find each other.
as a little pre-show surprise, here's an early draft of the permissioned data proposal! github.com/bluesky-social/proposals/pull…
Permissioned data by dholms · Pull Request #94 · bluesky-social/proposals
github.comAT Protocol Developers
Don't forget, @dholms.at is joining us for the livestream TOMORROW for a permissioned data AMA.
as a little pre-show surprise, here's an early draft of the permissioned data proposal! github.com/bluesky-social/proposals/pull…
Permissioned data by dholms · Pull Request #94 · bluesky-social/proposals
github.comAT Protocol Developers
Don't forget, @dholms.at is joining us for the livestream TOMORROW for a permissioned data AMA.
new proposal up for a JSON based XRPC subscription! give it a read & let us know your thoughts github.com/bluesky-social/proposals/tree…
proposals/0015-json-subscriptions at main · bluesky-social/proposals
github.comI think I found an issue with the existing Bluesky OAuth permission sets @matthieu.bsky.team @bnewbold.net: github.com/bluesky-social/atproto/issues…. The XRPC endpoints specified in `authViewAll` are inconsistent about aud. Minimal repro here. tangled.org/tylerjfisher.com/repro-bluesk… Might be doing something wrong, lmk!
Bluesky permission sets require inconsistent aud parameter · Issue #4850 · bluesky-social/atproto
github.comHi, I hear you on this. There's a longstanding issue with Bluesky's more granular permission sets I'm hoping to get resolved, which is blocking Sill from implementing a better set of permissions. github.com/bluesky-social/atproto/issues…
Bluesky permission sets require inconsistent aud parameter · Issue #4850 · bluesky-social/atproto
github.comjust in the nick of time! github.com/bluesky-social/proposals/tree…
proposals/0016-permissioned-data at main · bluesky-social/proposals
github.comdaniel holmgren 🫠
gonna get this permissioned data protocol proposal out at some point within the first 250 years of this nation's founding