Post
AT Protocol Developers
atproto.com
did:plc:ewvi7nxzyoun6zhxrhs64oiz
XRPC requests between atproto servers are authenticated using JWTs. There are some inconsistencies in how OAuth permissions, PDS proxy headers, and JWTs all represent the "audience" of these tokens.
This proposal gives background and describes a rough solution.
Looking for rapid feedback!
https://github.com/bluesky-social/proposals/tree/main/0013-service-auth-refs
2026-03-03T23:01:55.049Z