Authorize CI without exporting your ATProto session.
Relay verifies any configured OIDC identity, checks your claim policy, and forwards only the XRPC methods you allow.
The trust boundary stays visible
Each layer has one job. Removing a policy or session record revokes its access.
- Session custody
- Encrypted record on your PDS
- Workload proof
- Token from a configured OIDC issuer
- Claim authorization
- CEL expression you control
- ATProto access
- Explicit XRPC and collection allowlist