Case Study: Bluesky strengthens OAuth token security with WorkOS

A WorkOS Case Study

Preview of the Bluesky Case Study

Bluesky makes DPoP mandatory for every request with WorkOS

Bluesky, a decentralized social network platform, faced the challenge of securing its OAuth implementation against token theft, a significant risk given its open protocol and the inability to revoke tokens across a decentralized network. To address this, Bluesky partnered with WorkOS to implement Demonstrating Proof-of-Possession (DPoP), a sender-constraining mechanism defined in RFC 9449.

WorkOS provided the solution by implementing DPoP, which binds access and refresh tokens to a client-held cryptographic key pair. This required Bluesky's clients to sign every request with a fresh proof JWT, making any stolen token useless without the matching private key. The result was a fundamental hardening of Bluesky's security posture, effectively making token theft a non-event and providing robust protection for its users and the network.


View this case study…

WorkOS

82 Case Studies