#dpop
RFK Jr. thinks it’s okay to dig through the private medical records of millions of Americans for his autism 'study'? Nope. #DPoP #DisabilityRights #HandsOffOurData #CripTheLaw
April 23, 2025 at 5:03 AM
seeing dpop keys in my sleep
January 18, 2026 at 2:37 AM
Dpop demon hunters
January 18, 2026 at 3:35 AM
new shirt from dpop eek !! 🖤⭐️
May 17, 2026 at 2:29 PM
Well … I started a Dpop store, and sold 5 items today!!!

Woot.

#thrifting #dpop #store #sales
September 21, 2026 at 12:41 AM
Finally, I understand what DPoP is and why it exists. OAuth feels like such a maze of complexity but it is all there for a reason.
every time I go to work on millipds I decide I should do oauth next and then I start reading about how oauth works and get scared
Is anyone hosting a pds in prod that isn't running on the reference impl, or bridgy?
November 22, 2024 at 5:28 AM
I implemented AT Protocol (BlueSky) OAuth from scratch! Way harder than the usual implementation since it requires DPoP, client assertions, and some DNS stuff. Basic demo (source code in the next tweet):
atproto-oauth-example.vercel.app
November 5, 2024 at 5:55 AM
I'm pretty sure the biggest difference is our usage of dpop
July 4, 2025 at 5:08 PM
DPoP + IndexedDB でフロントエンドセッションをがっちり守る
#frontend #security #DPoP
DPoP + IndexedDB でフロントエンドセッションをがっちり守る
zenn.dev
May 25, 2026 at 12:25 AM
when you're trying to figure out why your OAuth server isn't working and then the problem is coming from inside the house cc @bnewbold.net @hailey.at
DPoP Spec Violation: atproto oauth clients include query parameters in `htu` field of DPoP JWT · Issue #3846 · bluesky-social/atproto
Describe the bug Here's a DPoP JWT produced by @atproto/oauth-client-browser: eyJhbGciOiJFUzI1NiIsInR5cCI6ImRwb3Arand0IiwiandrIjp7Imt0eSI6IkVDIiwiY3J2IjoiUC0yNTYiLCJ4IjoiM2dLTkV3Q3RkemJOakxDdDVzTGp...
github.com
May 10, 2025 at 3:04 AM
prior to beginning pds oauth implementation: the hardest part will be dpop

after beginning pds oauth implementation: the hardest part is validating e.g. jwt claims properly
June 16, 2025 at 6:52 PM
We condemn the Trump Admin’s decision to lay off half of the Department of Education. This will harm students with disabilities. We want to hear from current and former employees, students, and families, let’s protect our education system. #DPoP #StudentswithDisabilities
March 11, 2025 at 11:15 PM
so there's dpop and there's dpop nonce
July 17, 2025 at 4:11 AM
Just completely finished up the work to refactor and fix DPoP handling in @massicotte.org's OAuthenticator, thanks to @germnetwork.com for paying me to fix this!

github.com/ChimeHQ/OAut...
Rework DPoPSigner, fixing nonce tracking and other errors by ThisIsMissEm · Pull Request #50 · ChimeHQ/OAuthenticator
This completely reworks the DPoP Nonce handling, such that you have one DPoPSigner still, however, it is request-origin aware, and tracks DPoP Nonce's per origin. The DPoPSigner internally uses...
github.com
March 6, 2026 at 3:50 PM
we got password auth, we got app-password auth, we got bearer tokens, we got DPoP tokens, we got service tokens, we got...
January 20, 2025 at 12:31 AM
Non-exportable DPoP keys fix this, right?
Be aware that there are accounts attempting to steal session keys. This particular method won’t work using the Bluesky app for a couple of reasons, but third party apps may be vulnerable to similar attempts.

We will attempt to automatically label these as Platform Manipulation.
January 8, 2026 at 6:21 PM
you ever get so huge you cant hear anythign voer your squeaking and creaking, then try to flex an dpop yourself?
neither have i until this this shit sso niche lmaoooo but its HOT
art by @biolsharky.bsky.social‬
August 7, 2025 at 1:21 AM
tl;dr DPoP lets the auth server bind sessions to possession of some keypair. If the client stores the keypair securely (e.g. non-extractable WebCrypto keys), then a compromised auth token (e.g. leaked via XSS, passive SSL MitM) does not compromise the session as a whole.
Finally, I understand what DPoP is and why it exists. OAuth feels like such a maze of complexity but it is all there for a reason.
every time I go to work on millipds I decide I should do oauth next and then I start reading about how oauth works and get scared
November 24, 2024 at 9:05 PM
pls behold my “new” shirt from dpop it’s SO COMFY!!!!!!
July 15, 2026 at 4:47 AM
hot take: dpop is actually the easiest part of getting oauth going
July 17, 2025 at 4:05 AM
de la culture policière et la culture judiciaire. Côté police et gendarmerie, nous avons réalisé l'enquête DPOP avec soutien du Défenseur des Droits, accord de la PN /GN. Les agents ne sont que 15% à dire "on n'en fait pas assez sur la question des violences faites aux femmes"
June 16, 2026 at 1:37 PM
Today marks the anniversary of Judy Heumann’s passing. For many of us, Judy was a mentor, friend, advocate, and connector whose memory continues to guide our work. We remain dedicated to preserving and advancing her legacy. #DPoP #MarchFourth
March 5, 2025 at 1:05 AM
if I love DPoP so much why don't I marry it
February 24, 2026 at 8:27 PM
with that little addition, the backend that signs these client assertions has a conception of user sessions in the form of their dpop keys.

and can therefore revoke individual sessions or apply arbitrary session lifetime rules by simply refusing to sign a client assertion for a given dpop key. 5/8
June 5, 2025 at 2:36 AM
eeeeep!!! it’s rare to find acnh merch with my favorite NPC, sable, so when i saw this on dpop i knew i had to get it!!!!!
March 2, 2026 at 5:51 PM