#CreateAccount
PDS hosters: folks should not have PDS_INVITE_REQUIRED=false in their config unless they know what they are doing.

at a minimum you need CAPTCHAs on all signup routes, to block/disable the createAccount API flow, etc.

we know this should be smoother.
March 25, 2026 at 5:57 PM
Small PDS gatekeeper update

- Added rate limiter on the createAccount end point so you can set stricter rate limits
- No more hard exception if pds.env is not there
- Fixed a bug on getSession for oauth(whoops)
- Bit more logging on errors
createAccount stricter limits and more · pull #3 · @baileytownsend.dev/pds-gatekeeper
Microservice to bring 2FA to self hosted PDSes
tangled.sh
September 6, 2025 at 4:20 AM
open pdses are clearly causing a lot of problems and adding migration support to oauth sign up (specifying did at signup like you can on createAccount api) would allow us to disable the createAccount endpoint
Yes we have captchas but it doesn’t matter because we allow API signups to support migrations. I have been begging for OAuth signups to support migrations (signup with a specific did) for months (cc @bnewbold.net and @alex.bsky.team) because of the moderation nightmares api signup causes for us.
@knotbin.com is there captcha on sprk pds signup if you know?
March 3, 2026 at 10:23 PM
idk, just get mediawiki and set these options mayb
August 31, 2026 at 2:37 AM
YEAH, another MacPDS-project milestone - i.e. prototyping which might lead to a PDS running on MacOS, linux, Android, WSAM, Win…- :

createAccount worked !

Data in Postgress, HTTP 200 and did:plc looks reasonable …
Now I need to figure out what other PDS return …
😀
#codinginpublic #PDS #ATProtoKit
July 7, 2025 at 5:04 PM
How's this flow?
1. User enters email
2. Server silently calls createAccount on your PDS
3. DID provisioned, session token issued (all server-side)
4. User lands in the app and can write immediately
5. Send email: "you're signed in as @handle — tap to claim or edit your identity"
June 15, 2026 at 3:17 PM
yeah does nothing for account migrations and protecting the createAccount endpoint. So close
August 30, 2025 at 5:54 PM
#ATProto This is a very good question that made me realize something. I was gonna block the createAccount endpoint to stop bots from creating accounts without the oauth flow which includes a CAPTCHA. This is what bluesky does and they don't support inbound transfers...

But actually they do. 1/
Is it possible to transfer an existing account to Spark PDS? If yes, the removing of invite codes will probably be the time I'll host my account on my own PDS knowing that there is a way back to a public PDS.

(PS. I already have another account on Spark PDS.)
September 2, 2025 at 3:19 AM
Small setback.

✅ Get cocoon up and running
✅ Setup a test account
✅ Implement an S3 blob store
✅ Enable S3 backups
❌ Migrate a test account
☑️ Update cocoon createAccount to work with GOAT
☑️ Migrate a test account
☑️ Migrate my main account
☑️ Question my life choices
October 26, 2025 at 11:25 PM
One day! Need a whole ui and login for that if I want to keep my “no forking the PDS and client”

Next is adding gatekeeping for the createAccount endpoint with a captcha so admins can turn off the need for invite codes to stop bots
August 29, 2025 at 11:15 PM
yeah PDSes should probably have their own frontend eventually, not like it's especially hard for any app to implement createAccount though
December 31, 2024 at 11:29 PM
so long as you hold the keys to your identity you should be able to optionally swap the atproto verificationMethod and then craft a service JWT to createAccount
October 19, 2025 at 9:14 AM
for returning to bsky thats a requirement is it not? i think u need to createAccount (without existing did) before you can importRepo for their specific distribution
January 13, 2026 at 10:34 PM
This is only a problem for multi-user PDSs where the createAccount endpoint is not gated by invite codes. It looks like your software (micropod?) is single-user, so it's not impacted. Same with mine. My PDSs don't even *implement* createAccount.
March 25, 2026 at 6:51 PM
The installer, and then using the admin API to provision invites and createAccount to provision accounts, but be careful with this because you'll end up with usernames/passwords on the wrong host
April 9, 2026 at 6:51 PM
Gatekeeper has a couple of things you might like 👀. It can do captcha on the create account endpoint like Bluesky does, is a bit funky cause different services

But it also has a way to lock down createAccount for only account migrations and can do new accounts via oauth that you have the captcha on
February 21, 2026 at 10:08 PM
Let me know if there's something I can do to help 👀. The OAuth flow is the easiest to create new accounts. But if you're needing something to create a "shared" identity that others also have access to. May need to go the createAccount route. Let me know if there's something I can help with there!
ATProto devs did you know you can use selfhosted.social for users to create brand new accounts on the atmosphere in your applications? Both deckbelcher.com and blento.app uses our PDS. A user's journey into the atmosphere does not always have to be started from Bluesky. It can start from your app.
February 16, 2026 at 7:53 PM
the initial doc is only because the pbc pds requires that the createaccount call is signed for pre existing dids
February 5, 2025 at 7:13 AM
May 7, 2025 at 7:19 PM
I wish 😅

My latest thing I'm working on is a microservice that sits on top of the PDS(or beside it?). The big goal is you do not have to fork the PDS. But adds things like 2fa and possibly some other things for other endpoints like a captcha on createAccount

tangled.sh/@baileytowns...
@baileytownsend.dev/pds-gatekeeper
Microservice to bring 2FA to self hosted PDSes
tangled.sh
August 26, 2025 at 8:43 PM
Correct me if I'm wrong @bnewbold.net @divy.zone@hailey.at but the reason bluesky "doesn't support" inbound transfers is that it blocks the createAccount endpoint, which is what migrators use, right? but that's not the only way to create an account. 2/
September 2, 2025 at 3:19 AM
Ucho-ten作ってるときcreateAccount API使おうとしたらないはずのreCaptchaのコード要求されて「???」だったんだけど、やはりbsky.app経由しないとダメだったのか
September 20, 2025 at 11:19 AM
Two steps forward, maybe a step back.

✅ Get cocoon up and running
✅ Setup a test account
✅ Implement an S3 blob store
✅ Enable S3 backups
✅ Update cocoon createAccount to work with GOAT
✅ Migrate a test account
☑️ Fix calling authenticated feeds
☑️ Migrate my main account
☑️ Question my life choices
@hailey.at have you had any problems with accessing authenticated custom feeds using cocoon?

I'm getting feed generator rejecting because wrong aud / lxm claim in the token from proxying.

Reference PDS seems to have a special case for getFeed.
October 28, 2025 at 8:39 AM
An update on version 0.26 of ATProtoKit.

SessionConfiguration has nearly ready. I've made default implementations of createAccount, createSession, and getSession. refreshSession and deleteSession should be complete before the end of the day.
April 7, 2025 at 7:26 PM