Short answer: A Bluesky app password is a separate, revocable password you give to a third-party app instead of your real one. Create it in Settings → Privacy and security → App passwords, paste it into the app, and delete it whenever you want that app locked out.

Here is what an app password can and can't do, how to create one step by step, when to tick the direct-message box, how it compares with OAuth sign-in, and what to do if one leaks.

On this page:

The Direct Answer

Question Answer
Where do I make one? Settings → Privacy and security → App passwords
What does it look like? Four groups of four characters: xxxx-xxxx-xxxx-xxxx
Can I see it again later? No – it is shown once; make a new one if you lose it
Can it change my password or email? No – account-level changes need your real password
Can it read my DMs? Only if you tick the direct-message box when creating it
Can I revoke it? Yes – delete it and the app is signed out

What Is a Bluesky App Password?

An app password is a second password attached to your account that is meant for one app. It lets that app sign in as you, post, like, follow and read your timeline, while keeping your real password to yourself.

Three properties make it safer than handing out your main password:

  • It is limited. An app password can't change your account password, change your email, or delete your account. Those actions require the real password.
  • It is separate. You make one per app. If one app misbehaves, you revoke that one and the others keep working.
  • It is revocable. Deleting it locks the app out without forcing you to change your main password or sign out everywhere else.

App passwords are the standard way to sign in to bots, scripts, scheduling tools and older third-party clients. If you are writing your own bot, our TypeScript bot tutorial and the Python posting guide both use one.

How to Create a Bluesky App Password

The steps are the same in the iPhone, Android and web apps:

  1. Open Bluesky and go to Settings.
  2. Tap Privacy and security, then App passwords.
  3. Tap Add App Password.
  4. Give it a name that says which app will use it, for example skyscraper-appletv or my-bot.
  5. Leave Allow access to your direct messages off unless the app genuinely needs to read or send DMs.
  6. Tap Next and copy the password that appears. It is shown once.
  7. Paste it into the third-party app's password field, along with your handle.

The password looks like abcd-efgh-ijkl-mnop. Copy it straight into the app or into a password manager. Once you leave that screen, Bluesky only shows the name you gave it, never the password itself.

Name every app password

The name is the only way to tell your app passwords apart later. "Phone" and "Test" are useless six months from now. Use the app's name and, if you run it on more than one device, the device: scheduler-laptop, bot-raspberrypi. When you want to cut off one tool, you will know exactly which entry to delete.

Signing in with it

In the third-party app, enter your handle (or the email on your account) as the username and the app password as the password. If the app asks for a hosting provider and you never changed it, the default bsky.social is correct. If you moved your account, enter your PDS instead – see our guide to moving a Bluesky account to another PDS.

Should You Allow Direct Message Access?

When you create an app password, Bluesky asks whether it should be allowed to access your direct messages. Leave it off by default.

  • Turn it on for a full client you use to chat, such as a third-party app on another device.
  • Leave it off for bots, schedulers, analytics tools, backup tools and anything that only posts or reads public data.

An app password without DM access can still do everything public on your behalf, but it can't open your chats, including group chats. If you later find an app needs DMs, make a new password with the box ticked and delete the old one. You can't change the setting on an existing password.

Bluesky DMs are not end-to-end encrypted, so the protection here is about which apps can read them, not about the messages being unreadable on the server. Our Bluesky chat API guide covers how DM access works for developers.

How to Revoke an App Password

  1. Go to Settings → Privacy and security → App passwords.
  2. Find the entry by its name.
  3. Tap the delete (trash) icon and confirm.

The app using it loses access. It may keep working briefly while its current session token is still valid, but it can't sign in again or refresh that session. Do this whenever you:

  • Stop using an app or cancel a subscription to a tool
  • Sell, lose or wipe a device that had a third-party app signed in
  • See posts, follows or likes you didn't make
  • Can't remember what an old password was for

A tidy list is a safe list. If you have more than a handful of app passwords and can't name what each one does, delete the mystery entries; anything you still need will ask you to sign in again.

App Passwords vs OAuth Sign-In

Newer Bluesky apps sign in with OAuth: the app sends you to your account's own login page, you approve it there, and the app never sees a password at all. Apps can also ask for narrower permissions this way.

App password OAuth
App sees a password? Yes, the app password No
Where you log in Inside the third-party app On your account's login page
Works for bots and scripts Yes, easily Possible, but more setup
Revoke Delete the app password Sign out the app session

If an app offers both, OAuth is the better choice for an everyday client. App passwords remain the practical option for scripts, bots and devices where a browser login is awkward, such as a TV. Developers can read our Bluesky OAuth implementation guide for the details.

Never type your main password into a third-party app

Any app that asks for your real password, rather than offering OAuth or accepting an app password, is asking for more than it needs. Your main password can change your email and delete your account. If you have already done this, change your password in Settings and create an app password for that app instead.

What to Do If an App Password Leaks

Maybe you committed it to a public GitHub repository, pasted it in a screenshot, or a tool you used turned out to be shady. The fix is quick:

  1. Delete that app password in Settings. This cuts off whoever has it.
  2. Check your recent activity – posts, replies, follows and likes – for anything you didn't do, and delete it.
  3. Create a fresh app password for the legitimate app.
  4. Keep it out of code. Store it in an environment variable or a secrets manager, not in a file you commit.

You don't need to change your main password for a leaked app password, because the app password can't be used to change account settings. Do change it if you suspect your real password was exposed too, and turn on email two-factor authentication while you're there.

App passwords and two-factor authentication

Signing in with an app password does not ask for the email 2FA code. That is by design – bots can't read your inbox – but it means an app password is a key that works without a second factor. Treat each one as sensitive, and revoke the ones you don't use.

Frequently Asked Questions

Where do I find app passwords on Bluesky?

Open Settings, tap Privacy and security, then App passwords. That screen lists every app password by name and lets you add new ones or delete old ones.

What is the format of a Bluesky app password?

Four groups of four lowercase letters and numbers separated by hyphens, like xxxx-xxxx-xxxx-xxxx. Bluesky shows it once when you create it, so copy it immediately.

Can a Bluesky app password delete my account?

No. An app password can post, like, follow and read on your behalf, but it can't change your password or email or delete your account. Those actions require your main password.

Do I need to allow direct message access for an app password?

Only for a full client you use to chat. Bots, schedulers, analytics and backup tools don't need it. You can't change the setting later, so create a new password if you need DM access.

What happens when I delete an app password?

The app using it can no longer sign in or refresh its session, so it is effectively signed out. Your main password and every other app password keep working.

Do app passwords bypass Bluesky two-factor authentication?

Yes. Signing in with an app password does not ask for the email code, which is why each app password should be treated as sensitive and revoked when you stop using that app.

App Passwords in Skyscraper

Skyscraper supports both sign-in methods: OAuth with DPoP-bound tokens, or an app password. Accounts are stored in the Keychain, and you can sign in to more than one.

  • iPhone, iPad and Mac – sign in with OAuth, or use an app password if you prefer
  • Apple TV – sign in with an app password, so there's no typing your real password with the arrow keys (see Bluesky on Apple TV)
  • Alternate PDS support, including Eurosky

Download Skyscraper →