A technical deep-dive into how Decentralized Identifiers (DIDs) work within the AT Protocol (atproto) that powers Bluesky. Covers the structure of DIDs and DID Documents, explains the two DID methods supported by Bluesky — did:web (domain-based, simple but DNS-dependent) and did:plc (Bluesky's own method via plc.directory) — and discusses the trade-offs of each. Also addresses whether Bluesky truly owns your identity, how key rotation works, and how running your own PDS lets motivated users achieve genuine identity ownership independent of Bluesky.

9m read timeFrom steveklabnik.com
Post cover image
Table of contents
DIDs and DID Documentsdid:webdid:plcDoes Bluesky own your identity?In summary
930 Impressions