---
title: "@playstack/atproto"
description: "AT Protocol OAuth lifecycle through the official client without flattening DPoP and PAR into conventional bearer tokens."
tags: ["package","identity","atproto","bluesky","oauth","dpop","pro"]
---

{/* package-access:start */}

> **Pro.** Covered by the Playstack Pro License. Registry access is required; check preview availability before installing. See [package access](/docs/packages#access-policy).

{/* package-access:end */}

`@playstack/atproto` wraps the stable lifecycle of the official AT Protocol OAuth client. Discovery, PAR, PKCE, DPoP keys, nonces, refresh rotation, and session persistence remain with that client.

{/* package-install:start */}

## Install

After confirming [preview access](/docs/packages#access-policy), install the package at your application's shared Playstack version:

```sh
npm install --save-exact @playstack/atproto@0.1.0-beta.1
```

Check the peer requirements below before choosing a runtime or provider.

{/* package-install:end */}

## Compose without weakening the protocol

```ts
import { createAtprotoConnectionClient } from '@playstack/atproto'

const atproto = createAtprotoConnectionClient({ client: oauthClient })
const authorizationUrl = await atproto.begin({
  identifier: 'person.bsky.social',
  state: signedApplicationState,
})
const { session, identity } = await atproto.complete(requestQuery)
```

The stable DID can identify an application connection, but bearer tokens and DPoP private keys are not copied into `@playstack/connections`. Authenticated XRPC continues through the restored official session.

Node 20 uses `@atproto/oauth-client-node` 0.3.x. Node 22 and newer support 0.3.x through 0.5.x; the CLI selects the verified range for the active runtime.

{/* package-reference:start */}

## API entry points and requirements

Reference snapshot: `@playstack/atproto@0.1.0-beta.1`. Import only the entry point your runtime needs. Paths below are relative to the installed package; use **Go to Definition** in your editor to inspect exact parameters, return types and overloads. Do not import the declaration-file paths directly.

| Public entry point | Declaration file |
| --- | --- |
| `@playstack/atproto` | `./dist/index.d.ts` |
| `@playstack/atproto/package.json` | No TypeScript declaration (asset or metadata export). |

Node.js engine requirement: `>=20`. This is not a claim that every entry point works in browsers or Workers.

### Peer dependencies

Keep existing framework versions that satisfy these ranges. Install optional peers only when using the corresponding adapter. The package manager resolves ordinary dependencies separately.

| Peer | Compatible range | When needed |
| --- | --- | --- |
| `@playstack/connections` | `0.1.0-beta.1` | Required by the package. |

For a complete first program, start with [Getting started](/docs/getting-started). For API lookup and partial-example conventions, see [Reading the reference](/docs/packages#reading-the-reference). Provider failures, lifecycle requirements and application responsibilities remain described in the guide above; types alone do not establish production safety.

{/* package-reference:end */}
