







A trustless, secure, local-first, user-originated, distributed authorization scheme.
UCAN Working Group
Decentralized Auth — User Controlled Authorization Networks - UCAN Working Group
Enterprise-Managed Authorization: Zero-touch OAuth for MCP
The Enterprise-Managed Authorization extension to the Model Context Protocol is now stable, enabling organizations to centrally provision MCP server access through their identity provider so users get connected servers on first login without per-app OAuth.

Building AIP: An ATProtocol Authorization Gateway - Nick's Blog
OAuth is the first challenge developers face in the atmosphere. This post is about AIP, the authorization gateway we built at Graze Social to alleviate some of the pain.
WAVE: A Decentralized Authorization Framework with Transitive Delegation | USENIX
Michael P Andersen, Sam Kumar, Moustafa AbdelBaky, Gabe Fierro, John Kolb, Hyung-Sin Kim, David E. Culler, and Raluca Ada Popa, University of California, Berkeley

OAuth for AT Protocol | Bluesky
We are very happy to release the initial specification of OAuth for AT Protocol! This is expected to be the primary authentication and authorization system between atproto client apps and PDS instances going forward, replacing the current flow using App Passwords and createSession over time.


OAuth Patterns - AT Protocol Docs - AT Protocol
Auth for AT Protocol application developers.

OAuth Patterns - AT Protocol Docs - AT Protocol
Auth for AT Protocol application developers.



Service Auth | Bluesky
There are currently two "types" of auth supported in the atproto network: client-server auth and service-to-service auth.

Keyhive: Local-first access control
Keyhive is a project exploring local-first access control. It aims to provide a firm basis for secure collaboration, similar to the guarantees of private chat but for any local-first application.

`rs-ucan`: Rust crates to support UCAN-based authz · Issue #668 · filecoin-project/devgrants
Open Grant Proposal: rs-ucan Name of Project: rs-ucan Proposal Category: core-dev Proposer: @cdata (Optional) Technical Sponsor: @autonome Do you agree to open source all work you do on behalf of t...