







you're working on an atproto app that needs to write some records to your own collection like app.example.post or app.example.like. you're already using OAu…
ATProto User Intents Demo
This is a demo tool which allows atproto accounts to configure a reuse declaration for their public data. You can read more about this atproo mechanism in the "User Intents for Data Reuse" proposal from March 2025. Any account in the atproto network (including Bluesky accounts) can use this tool via OAuth. The source code for this demo is linked above.
atproto made simple: granular permissions - underreacted
Building OAuth Authentication for ATProto apps: Part 1, the web use-case - Building on atproto
In this follow-up OAuth implementation guide I dive a bit deeper into the actual implementation details of building authentication for your web or mobile app that builds on top of ATProto.

Building a Browser-Based ATProtocol OAuth App with Supporter Validation - ATProtoFans Blog
OAuth for ATProto Apps Part 2: Mobile Implementation - Lost in Inference
Part 2 of a 2-part series on implementing OAuth authentication for ATProto (Bluesky) applications.
index.html · by atprotofans.com
An browser-side ATProtocol OAuth application with no dependencies that verifies supporters
Beyond the Statusphere: Part 2, ATProto OAuth, the TLDR - Hitchhiker's Guide to the Atmosphere
Gain a working knowledge of ATProto OAuth and feel confident implementing it in your projects.

OAuth Improvements - AT Protocol
We've been making improvements to the end-user and developer experiences with atproto OAuth.

an atproto permissioned data pattern i hope/expect to see flourish is apps using the "simplespace" authority on the user's PDS and not minting any space credentials at all, just using oauth portable, private data that the user can selectively expose without necessarily revealing the atproto records
here's my take on a minimal oauth browser client for atproto! no special API client class — just use plain `fetch` to make requests and a service worker automatically handles authorization headers/token refreshes/dpop retries/etc. (very experimental, not tested in production, use at your own risk)
jakelazaroff.com/atsw
tangled.org@dholms.at motivated me to make a follow up post on Stratos, @transrights.northsky.social approach to permission data on ATproto! This one is a bit of a brief technical overview and as a nice bonus, I've made the code base public.
Stratos: Lets get Technical
chipnick.com
import.py
Archivers AT

Brickster — Build anything, together.

BlueHarbor

Kimbia - A training journal that belongs to you.

Currents