BLUE
Profile banner
WM
Watch Medabots
@thebrows.bsky.social
Paige | she/they | EN, 日本語(独学) | FUB Free Software Dev by day | Phantom Thief (appreciator) by night | Digital Artist when motivated | #art | Please do not repost my art Enstars, PjSekai, Splat3, seasonal anime TheBrows.carrd.co
23 followers283 following30 posts
WMthebrows.bsky.social

PSA for anyone using third party tools such as SkyFeed, Sky Follower Bridge, etc. You do not need to provide the password you use for login! Use App Passwords! They're meant for safer access control of third-party apps, and can be generated and deleted at any time! Read the ALT text for more info!

A screenshot of the Bluesky Settings page, showing the location of the link to the "App Passwords" page. It is the first link under the "Advanced" section of the Settings page, on both the mobile app and browser versions of the Bluesky app.
A screenshot of the App Passwords page, showing a list of my current App Password entries.

Each entry shows the title you provided for the App Password, as well as the date and time at which it was created. Each App Password entry also has a red trashcan icon on the right side of the App Password entry to permanently delete the App Password. This feature makes the App Passwords great for third-party app use, as you can make one App Password per app, and instantly delete the App Password and that app's access to your account in cases of malicious use or data breach.

There are currently two App Passwords on my account shown in the list of App Passwords in the screenshot. The top entry is titled Sky Follower Bridge, which I use with the Sky Follower Bridge Chrome extension, used for finding Twitter/X followers on Bluesky. The second entry is titled SkyFeed, which I use with the third party app SkyFeed at skyfeed.app for creating Bluesky feeds.

At the bottom of the page, under the list of App Passwords, is a button "Add App Passwords" to create a new App Password.
A screenshot of the popup prompt after clicking the Create App Password button on the App Passwords page of the Bluesky Settings. It prompts you for a unique name for the new App Password, which is the name that will display on the entry for the App Password on the App Passwords page. It provides a randomly generated name in the text field by default, which in the case of this screenshot is "CadetBlue". It requires that the unique name only contain letters, numbers, spaces, dashes, and underscores, and must be between 4 and 32 characters long, inclusive.

Below the unique name prompt, there is a checkbox for allowing access to your direct messages, which is disabled/unchecked by default.

Below that is another button "Create App Password" to confirm your choices and generate the App Password.
A screenshot of the next popup following your confirmation to create the App Password. It will show the App Password on this popup, with a button to copy the password to your clipboard. In this image, the password has been manually censored by me with a big red opaque block digitally added to the screenshot, covering the whole password, though I've also already deleted the password from this screenshot.

Under the password is an important note: "For security reasons, you won't be able to view this again. If you lose this password, you'll need to generate a new one." As this is the only time the actual password will be shown to you, you will need to copy and paste it to a secure location, such as a trusted password manager, or directly into the third party app you are using the password with, before navigating away from the popup. The App Password entry will show on the App Password page after closing this popup under the name you previously chose, but not the password itself.

At the bottom of the popup is a "Done" button to close the popup.

As best security practice, be mindful to only give these passwords to trusted sources, as they provide access to large scopes of your Bluesky account. 

Research third-party apps in advance to determine that they are safe before providing your password to them. For example, third-party apps following best practices will ideally store your password in non-permanent and/or local storage locations, such as your browser's session cookies.

Additionally, no official Bluesky source, such as Bluesky support, should ever ask you for existing or new Bluesky App Password(s) from your account over DMs or the like. 

If you believe your App Password may be compromised, delete if from the App Passwords page as shown in the previous screenshot. If someone does receive access, the password does not include scopes for destructive actions such as account deletion or migration. They are also restricted from creating additional App Passwords.
0

Profile banner
WM
Watch Medabots
@thebrows.bsky.social
Paige | she/they | EN, 日本語(独学) | FUB Free Software Dev by day | Phantom Thief (appreciator) by night | Digital Artist when motivated | #art | Please do not repost my art Enstars, PjSekai, Splat3, seasonal anime TheBrows.carrd.co
23 followers283 following30 posts