Connections
Authorize, encrypt, refresh, and revoke third-party credentials without moving provider APIs or product workflows into a generic abstraction.
AT Protocol sessions
Use the official AT Protocol OAuth client while keeping discovery, PAR, PKCE, DPoP, nonces, and session storage intact.
Visit AT Protocol ↗Authorize, encrypt, refresh, and revoke third-party credentials without moving provider APIs or product workflows into a generic abstraction.
AT Protocol sessions
@playstack/atproto wraps the official OAuth client rather than flattening AT Protocol into a conventional access-and-refresh-token driver. The official client retains discovery, PAR, PKCE, DPoP keys and nonces, rotating refresh tokens, and its durable state and session stores.
import { NodeOAuthClient } from '@atproto/oauth-client-node'
import { createAtprotoConnectionClient } from '@playstack/atproto'
const atproto = createAtprotoConnectionClient({
client: new NodeOAuthClient(configuration),
})Playstack exposes the stable DID as a provider identity for application connection records. Authenticated XRPC continues through the restored session's fetchHandler, so bearer tokens and DPoP private keys are not copied into the generic Connections credential model.
Node 20 applications use @atproto/oauth-client-node 0.3.x. Node 22 and newer can use the verified 0.3.x through 0.5.x range; the CLI selects the compatible range from the active runtime.