#JWTS
XRPC requests between atproto servers are authenticated using JWTs. There are some inconsistencies in how OAuth permissions, PDS proxy headers, and JWTs all represent the "audience" of these tokens.

This proposal gives background and describes a rough solution.

Looking for rapid feedback!
proposals/0013-service-auth-refs at main · bluesky-social/proposals
Bluesky proposal discussions. Contribute to bluesky-social/proposals development by creating an account on GitHub.
github.com
March 3, 2026 at 11:01 PM
if you're working on video games i hope you AT MINIMUM know the history of emigration policy, JWTs, how to use perlin noise, HLSL, all your trigonometry, what a high pass filter is, color grading...
I've always done too much at the same time (enterprise job + caves of qud + other enterprise side gig), but right now every thing is a game thing and it's pretty fun but also games is really hard lol ever game is such a fucker.
July 26, 2025 at 1:58 AM
CAN ATP PLEASE BE NORMAL SOMETIMES LITERALLY NOBODY ELSE DOES K256 JWTs
April 10, 2024 at 2:53 AM
This is a technical limitation of JWTs not specific to Microsoft. Every website with a “Sign me out of everywhere” button has the same limitation because the “I am logged in” data is not stored on Microsoft servers.
March 5, 2025 at 11:14 PM
Don’t use createSession every time

Hold onto the jwts and then use refreshSession
November 9, 2024 at 5:32 PM
It’s crazy how many CVES there are from people accepting JWTs with “alg: none”.. kind of makes me understand why programmers are worried they will be unemployable
April 18, 2026 at 9:41 AM
gonna have nightmares about jwts tonight
August 16, 2026 at 10:48 PM
Also fucked right now, JWTs. Many uses of JWT are fine, but based on the enterprise integration patterns I've seen, many are **not**.
June 7, 2026 at 7:48 AM
My jwts are all out of sorts
August 6, 2024 at 4:02 AM
what's really nuts is how many people consider JWTs the pinnacle of engineering and shove them anywhere authentication is needed

like IRC
April 18, 2026 at 11:37 AM
should there be a way to self-sign XRPC JWTs and authenticate to the PDS that way? eg, uploadBlob, change account status
May 14, 2026 at 6:45 PM
Tired of relying on third-party auth providers? Take control of your authentication!

With @expo.dev Router, you get full flexibility—manage your own JWTs, securely integrate any auth provider, and protect API routes with ease.
March 21, 2025 at 2:30 PM
Do they know about your JWTs being incorrectly formatted???
August 6, 2024 at 5:46 PM
Oh, I just realized quantum computers (and the massive size of ML-DSA signatures) will probably kill asymmetrycally-signed JWTs as bearer tokens. This is good.

90% of the time, asymmetric signatures are unnecessary complexity, and a session ID or HMAC would do just as well.
August 18, 2026 at 5:29 PM
streamplace isn't letting us log in, something wrong with JWTs :(
September 27, 2025 at 5:07 PM
Need authentication in your Swift backend? Paul Toffoloni has you covered in this new article on JWTs in Swift:
swiftonserver.com/2025/jwt-kit/
Introduction to JWTs in Swift - Swift on server
Learn how to use JWTs in Swift to secure your API
swiftonserver.com
January 9, 2025 at 6:14 PM
logging into the jwst with my jwts
August 7, 2026 at 10:45 PM
aha xrpc describes inter-service auth jwts exactly what i want yipee
October 16, 2025 at 8:26 AM
Base64 encoding is everywhere on the web: in HTTP headers, JWTs, even in HTML. But what is it and how does it actually work?

I break it down in my latest video!

Watch now: youtu.be/8v4moossLXo
July 30, 2025 at 2:00 PM
Haha obrigada @cuducos.me ! @gleiceellen.bsky.social vê se esse blog post te ajuda auth0.com/blog/pt-how-...

Se não ajudar me manda uma DM fazemos uma chamada pra ver juntas :)
Como Lidar com JWTs em Python
Aprenda a criar, encode, parse, decode e verificar seus JWTs em Python usando PyJWT
auth0.com
March 6, 2025 at 5:06 PM
No quiero curraaaaar

Odio los JWTs
October 8, 2025 at 7:15 AM
"When using OIDC, you configure IAM to accept JWTs from GitHub's OIDC endpoint."

listen bub I just wanna make sprite go blam
April 10, 2025 at 10:17 AM
I guess someone must've updated the AppView to require the lxm in JWTs because now I can't see anything on this app. Write-only Bluesky. This is literally exactly the opposite of the problem I had last time I didn't update my PDS
August 18, 2024 at 9:42 PM
good things take time - we just shipped one of the most requested features for @supabase.com Auth:

◆ asymmetric JWTs
◆ new API Keys for better security

There are no breaking changes. You can opt in today then opt-out of the old keys whenever you want. Massive performance boost
July 14, 2025 at 2:12 PM