Skip to content
OIDC access for ATProto

Authorize CI without exporting your ATProto session.

Relay verifies any configured OIDC identity, checks your claim policy, and forwards only the XRPC methods you allow.

Connect an account

Sign in with ATProto to store an encrypted automation session on your PDS.

Relay never sends your ATProto token to the workload.

The trust boundary stays visible

Each layer has one job. Removing a policy or session record revokes its access.

Session custody
Encrypted record on your PDS
Workload proof
Token from a configured OIDC issuer
Claim authorization
CEL expression you control
ATProto access
Explicit XRPC and collection allowlist