epds-login
Implementing ePDS Login
ePDS lets your users sign in to AT Protocol apps — like Bluesky — using familiar login methods: email OTP, Google, GitHub, or any other provider Better Auth supports. Under the hood it is a standard AT Protocol PDS wrapped with a pluggable authentication layer. Users just sign in with their email or social account and get a presence in the AT Protocol universe (a DID, a handle, a data repository) automatically provisioned.
From your app's perspective, ePDS uses standard AT Protocol OAuth (PAR + PKCE + DPoP).
The reference implementation is packages/demo in the ePDS repository.
For protocol-level detail beyond ePDS specifics — DPoP proof mechanics, granular
scope design (repo:/rpc:/blob:/account:), identity verification after token
exchange, and refresh-token race handling — see the atproto-oauth skill. This skill
covers only what is ePDS-specific.