OAuth: What It Is and What It Does
The story of an oft misunderstood piece of technology, and one that powers a significant portion of the Atmosphere
OAuth = Open Authorization
Okay so you know how you can "Sign in with <enter a ton of different services here>"? That's OAuth. It's basically the process of logging into one service in order to log into many others.
This works by sending what's called a token, which you can think of as a hall pass. Hall passes are only allowed to be signed or given out by certain individuals, not just anyone can give you permission to access something. When you show up to the other service, all you have to do is get it that token, which is done by logging in to the other service.
Example
You want to log into Uber. Uber allows you to Sign in with Apple, meaning that Apple is one of the "teachers" allowed to sign your hall pass. When you show up to the Uber app and it asks for that pass, you log into your Apple Account and give it the signed hall pass (a signed access token).
Example 2
Another way to think about it is like TSA. American Airlines doesn't do security screening, just like an app like The Social Wire doesn't ask for a username or password.
You go through security at the TSA checkpoint and that's it. You're good from there. You can go to your gate, you can go to other concourses, and you can even go to other airports if you have a connection. Because the TSA already screened you, everyone else trusts that you are safe and allowed to be there.
Obviously, there are security checks, you're not just allowed to roam free on the internet without logging into anything. These "tokens" that are handed out when you sign in expire. After a set amount of time you have to log in again.
How It Works for Bluesky
So, when you log into a site like https://bsky38.com or https://pckt.blog, you're not actually logging in there. What happens is that you give them your Bluesky handle and it looks it up in a "phonebook" called the PLC (The Public Ledger of Credentials). Without going too deep into it, this is basically a map of handles to accounts. The PLC tells the site you're logging into which website actually has your account data (usually Bluesky).
When it gets that information, it takes you from bsky38.com to bsky.social, which is where your Bluesky account lives. You log into bsky.social just like you would when you log into the Bluesky app, and then Bluesky tells bsky38.com whether or not you are the person you say you are.
The Upsides
- You don't need a ton of accounts. Your one Bluesky account gets you access to all kinds of different websites (which can be found at https://atstore.fyi).
- You never have to give your information to another website. Everything you do is stored in your Bluesky account, not on other servers.
The Downsides
- Idk, it's kinda confusing. Like "you're saying I can log into this website by logging into another website?" Yup. That's exactly it.
Why This Matters
OAuth is a really powerful tool that helps make the internet safer and easier to use. You don't need a ton of different accounts with a ton of different usernames and passwords. You don't need to trust a ton of different websites with a username and password that could get leaked (I mean, don't go leaking your Bluesky password), but there are fewer failure points.
In the world of usernames and passwords for every site (called "basic authorization"), any one of the sites could leak your information, no matter how secure the other sites are. The chain of security is only as strong as the weakest link. With OAuth, you only ever have to trust the strong links.
Got any questions? Leave a note! I'm happy to help explain anything in more detail!
