Your AT account guide

Use a professional page to point to originals, explain your contribution and say what the work does not prove. An account connects the page to you; it does not verify your claims.

Bring an account, not a new server.

AT Protocol connects accounts and their public data across personal data servers, or PDSs. An existing account from a compatible provider—including many Bluesky accounts—can be used without running your own server or buying a domain.

Your handle is the readable account name. Your DID is its persistent identifier. The intended from.work page link uses the DID and reads your current professional record from your current PDS. Provider compatibility still needs live testing; not every service or browser is qualified.

No account yet? Choose a provider, read its terms and create your account there yourself. Meanwhile, the work index needs no account. from.work does not import LinkedIn contacts, recommendations or private messages.

What scoped sign-in means

When public sign-in opens, use the separate member site. It sends you to your provider’s OAuth consent screen. The requested permission is atproto repo:work.from.workIndex: account authentication and writing this professional-page collection. It is not permission to post to your Bluesky feed, read private chats, upload blobs or manage your account.

The collection scope can cover multiple records in that collection; this editor uses only self. Your browser holds the scoped session. Scripts on the member origin can access it, which is why the member site must be separate from marketing and the demo, with no third-party scripts. Do not sign in on a shared or untrusted device.

A page you choose to make public.

These are the intended steps for the AT editor when public access is approved. Signing in alone will not publish anything.

  1. Sign in with your provider. Inspect the account and granted permission. You can deny access. Keep credentials on the provider’s own screen.
  2. Start a draft or explicitly import your snapshot. Paste a full from.work snapshot link only if you may use its contents. Browser drafts and old links are never silently uploaded. A snapshot is not evidence of identity, authorship or consent.
  3. Choose up to six originals. Open each public link and check it works without sign-in. Write your own contribution, context and limits. Do not paste private reference quotes, client information or signed access links.
  4. Review and consent. Check every displayed field, reconfirm rights and explicitly choose public AT publication. The editor reads the record back before reporting success.
  5. Share the current page. A DID-based page reads the current record. An older snapshot stays a separate fixed copy and does not update.

Editing requires another review. If someone edited the PDS record elsewhere, a CID check—a check against the version you loaded—stops a stale overwrite. Keep or export the draft, reload and reconcile; do not repeatedly publish after an uncertain response.

Public is not “just our group.”

Your name, professional summary, work URLs, titles, contributions, context and limits become public AT records. Other people and services can read, copy and index them without joining from.work. No private references, contact list or membership list is included in this page record.

Three different permissions: publishing your page, appearing in a group directory, and disclosing a contact destination. None implies the others. Public authors must not be enrolled automatically. A group will need separate opt-in, human review, private reporting, removal and appeal arrangements before launch.

Discovery uses a handle resolver, the public PLC directory and your PDS. Those services receive requests including your IP address and queried identifiers. Hosting providers also receive ordinary page requests. Work links open at their original sites; those sites have their own privacy policies.

Deleting a current record cannot recall other people’s copies, old snapshot links, search indexes or source material. A public URL is not permission to copy its contents or a guarantee that you may disclose it.

Know what the page does not prove.

The new schema is not yet published as an authoritative Lexicon. Local protocol tests and fictional users are not evidence that real members find the product useful, that every provider works, or that a group is safe to launch.

Start with one piece of work.

The working account-free route is available now. Open the original, describe your part, preview it as a commissioner and choose whether to make a share link. You can use existing email or another agreed channel to send it.

Build a work index →

For protocol details: AT Protocol overview · OAuth specification · Permissions.