Skip to content

Conversation

@disnet
Copy link
Owner

@disnet disnet commented Jan 21, 2026

Per AT Protocol OAuth spec, login_hint should be the account identifier the user entered (handle) to ensure recognition on the auth screen. Previously we were passing the DID, which users wouldn't recognize. The security benefit is preserved as Bluesky's auth server still restricts authentication to the resolved account.

🤖 Generated with Claude Code

Per AT Protocol OAuth spec, login_hint should be the account identifier the user entered (handle) to ensure recognition on the auth screen. The security benefit is preserved as Bluesky's auth server still restricts to the resolved account.

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
@disnet disnet merged commit 01d5a15 into main Jan 21, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants