jola

jola

As part of building a service for automatically publishing blog posts from RSS feeds into atproto’s standard.site lexicon, I implemented atproto OAuth for logging in and getting access tokens to publish for the user. This means that any user with an atproto account, whether they created it on Bluesky, Eurosky, or Blacksky, or any of the other Personal Data Servers available, can log in to your service. Atproto OAuth does not require pre-registering clients with a service, one implementation works across the entire ecosystem.

The OAuth implementation is based on the 2.1 specification with some still in-draft extensions, and comes with some quirks compared to what you’d expect from older generations of OAuth. For example, access tokens can’t be used as is, they need to come with a DPoP (demonstrating proof of possession) header signed for the specific request you’re making, limiting what the access token can be used for if stolen. Additionally it includes PAR (push authorization request) and some other fun stuff.

The goal of Latch is to provide an idiomatic Elixir implementation that deals with all of this for you, while maintaining flexibility and enabling things like setting up multiple OAuth clients in the same project, and starting them ad-hoc on command.

Quickstart

Add Latch to your project.

def deps do
  [
    {:latch, "~> 0.5.0"}
  ]
end

Create a Latch Store module for storing in-progress requests and access tokens.

defmodule MyApp.LatchStore do
  use Latch.Store.ETS
end

Add it and your Latch instance to your supervision tree.

children = [
  {MyApp.LatchStore, []},
  {Latch,
    name: MyApp.Latch,
    mode: :confidential,
    store: MyApp.LatchStore,
    client_id_path: "/oauth-client-metadata.json",
    redirect_uri_path: "/auth/callback",
    base_url_fn: &MyAppWeb.Endpoint.url/1,
    scope: "atproto",
    signing_key: System.fetch_env!("ATPROTO_CLIENT_PRIVATE_JWK")}
]

Set up a route to serve the CIMD (client ID metadata document) at /oauth-client-metadata.json.

def client_metadata(conn, _params) do
  json(conn, Latch.client_metadata(MyApp.Latch))
end

Now the rest of it is fairly recognizable if you’ve done OAuth before. Call authorize when a user has passed their handle to log in, redirect them to the URL you get back, and then provide a callback URL to finish the flow.

# call when the user clicks log in
{:ok, url} = Latch.authorize(MyApp.Latch, "alice.bsky.social")
# send to the user to the url

# expose a callback endpoint and call callback
{:ok, %{did: did, handle: handle}} = Latch.callback(MyApp.Latch, conn.params)
# and you're done, the access token lives in Latch

Now you can hit private endpoints or write to the user’s atproto PDS, according to the scopes you requested. Here’s are some example requests. Note that access tokens are managed and refreshed automatically by the library.

{:ok,
  %{
    "uri" => "at://did:plc:abc123/app.bsky.feed.post/3k2...",
    "cid" => "bafyreid...",
    "value" => %{
      "$type" => "app.bsky.feed.post",
      "text" => "Hello atproto",
      "createdAt" => "2026-07-31T12:00:00.000Z"
    }
  }} =
  Latch.query(MyApp.Latch, did, "com.atproto.repo.getRecord",
    params: [
      repo: did,
      collection: "app.bsky.feed.post",
      rkey: "3k2..."
    ]
  )

{:ok,
  %{
    "uri" => "at://did:plc:abc123/app.bsky.feed.post/3k5...",
    "cid" => "bafyreig..."
  }} =
  Latch.procedure(MyApp.Latch, did, "com.atproto.repo.createRecord", %{
    repo: did,
    collection: "app.bsky.feed.post",
    record: %{text: "Hello atproto", createdAt: DateTime.utc_now()}
  })

I’ve previously written a bit about atproto and Latch on https://blog.annot.at. I’m also planning to write more on my personal blog!

Where Next? Top

Trending in Announcing Top

wojtekmach
Hey everyone! Req is an HTTP client for Elixir that I’ve been working on for quite some time. There is already a lot of HTTP clients out...
New
handnot2
Samly can be used to enable SAML 2.0 Single Sign On in a Plug/Phoenix application. This library uses Erlang esaml to provide plug enabl...
New
woylie
Flop is an Elixir library that applies filtering, ordering and pagination parameters to your Ecto queries. offset-based pagination with...
New
MRdotB
I needed to reuse React components from my Chrome extension in my Phoenix/LiveView backend. I noticed that for Svelte/Vue, there are live...
New
garrison
Hobbes is a low-level distributed database for the Elixir programming language. Hobbes provides a simple, safe, and scalable storage lay...
New
marciok
Hi there! We created Gust: A task orchestrator inspired by Airflow. For those who have never heard about Aiflow, it’s a Python-based wor...
New
fuelen
Hi all! I want to present a small library which provides a mix task for generating an Entity-Relationship Diagram for Ecto schemas. You...
New

Other Trending Topics Top

mudasobwa
I am happy to introduce the very α version of the new programming language compiled to BEAM. Welcome Cure. It has literally three kille...
New
mudasobwa
I am seeing a lot of aplications of Argumentum ad Vericundiam in software discussions. They do link some piece of writing and point us to...
New
AstonJ
This showed up on my feed.. anyone heard of it? Just hype? Ox Alpha is a reasoning model designed for coding, sustained ag...
New
sergio
It’s not that it’s vocabulary is too advanced. It’s something worse. I get lost trying to follow even a paragraph written by Claude. It’...
New
sorenone
Today we’re releasing Oban for Python. Not an Oban client in Python. Not a pythonx wrapper embedded in Elixir. Nope, it’s a fully operati...
New
akoutmos
@hugobarauna, Dr. Dimitrios Koutmos (my brother) and I (Alex Koutmos) have been hard at work on writing a book on how you can use Elixir ...
New

We're in Beta

About us Mission Statement

Options

Thread Display Mode




Thread Preview

Skip Thread Previews