How Bluesky credentials are configured today
A working Bluesky API client already exists in this codebase, using an app password rather than OAuth, but nothing in the product calls it yet. This guide explains the real credential mechanism and deployment variables honestly, rather than describing a connect flow that does not currently run.
1 What exists today
A real, working Bluesky client exists in this codebase, capable of authenticating, posting, and reading a timeline against the AT Protocol. However, nothing currently invokes this client; there are no routes, workers, or UI elements that call it. This status is confirmed by the deployment's connector catalogue, which lists the integration as existing but unreachable. A repository-wide search also verifies that no module outside the client's own file imports it.
2 Bluesky uses an app password, not OAuth
Unlike the platforms supported by Socie's connect wizard, Bluesky does not use an authorize-code OAuth flow. There is no browser redirect, no client ID or secret, and no scopes involved in the authentication process. Instead, the system uses an app password generated in Bluesky's Settings to exchange for a short-lived session token. This session token is created fresh on every call rather than being cached.
3 Set the handle and app password
To configure the credentials, set the account's handle and a generated app password in your environment. The client requires both of these variables to function and does not accept the account's main password. The system creates a new session for every API request rather than caching the token in memory. This design choice prevents cross-workspace token leakage, similar to how the deployment's YouTube client handles access tokens.
4 Point at a different service, if you run one
By default, the client communicates with Bluesky's public entryway at bsky.social. If your account resides on a self-hosted Personal Data Server or a different App View, you can override this default address. Setting the service URL variable directs all API calls to your specific server instance instead of the public one.
Next
Status: reviewed · reviewed by gemini-3.8-flash