SYSTEM Cited by 1 source
AT Protocol (atproto)¶
What¶
AT Protocol (atproto) is an open, decentralized network protocol for social and application data — the protocol that powers Bluesky and a growing ecosystem of applications. Its defining property is that identity and data are owned by the publisher, not by any single platform or catalog: a user's account (in atproto terms, a repository identified by a decentralized identifier) holds their signed records, and any number of independent services (indexers, catalogs, moderation labelers) can read, aggregate, and apply their own policies over those records without owning them.
On this wiki, atproto is documented as the substrate under EmDash's decentralized plugin registry (2026-09-28). It is a real named protocol (proper noun) — exempt from the concept/pattern taxonomy gate.
Core architecture (as used by the EmDash registry)¶
- Repositories signed by the account holder. In the EmDash registry, plugin package and release records are signed by the publisher and stored in the publisher's own account — so the authoritative record lives with the publisher, and a catalog only mirrors it. (Source: sources/2026-09-28-cloudflare-emdash-10-the-stable-cms-with-a-secure-plugin-registry)
- Portable identity (Atmosphere accounts). Publishers use an Atmosphere account — the same portable identity used across Bluesky and other atproto apps. Because identity is not tied to a single marketplace, a publisher whose listing is removed from one catalog keeps the same identity and release history and can be indexed elsewhere. This is the decentralized / self-sovereign-identity move: the publisher owns the namespace, not the platform.
- Signed Merkle Search Trees + inclusion proofs. "Atproto repositories use signed Merkle Search Trees, so an inclusion proof connects the exact release record to a signed commit from the publisher's account." A consumer (EmDash) can therefore verify a record independently instead of trusting the catalog's copy — the Merkle structure is a verifiable data structure: tampering with any record invalidates the inclusion proof against the signed root. (Merkle Search Tree / inclusion-proof recorded here as prose + tag; not yet minted as a standalone concept — single-source on this wiki.)
- Separable catalogs + moderation (labelers). atproto's design lets multiple services index the same publications and "build their own catalogs, and apply their own policies." Moderation happens via labeler services that annotate what a given catalog displays (names, descriptions, links, images) without rewriting or taking ownership of the underlying publication. EmDash's labeler uses Workers AI to moderate package descriptions.
Why it fits the "registry that doesn't own the ecosystem" thesis¶
Traditional package registries fuse three roles — the publisher's account, the authoritative package record, and the discovery catalog — making one company the gatekeeper for both identity and distribution. atproto decouples them: identity + authoritative signed records sit in the publisher's repository, while catalogs are interchangeable read-side views. This is the structural mechanism by which EmDash breaks the plugin-marketplace-lock-in dynamic (contrast the WordPress.org marketplace, where GPL inheritance + same-process execution lock plugin authors to the marketplace). See systems/emdash and concepts/capability-based-sandbox for how the sandbox model complements this at the execution layer.
Seen in¶
- sources/2026-09-28-cloudflare-emdash-10-the-stable-cms-with-a-secure-plugin-registry — canonical wiki instance. atproto is the substrate for EmDash 1.0's decentralized plugin registry: publisher-signed package/release records in Atmosphere accounts, signed Merkle Search Trees + inclusion proofs for independent verification, and separable catalogs + Workers-AI labeler moderation that never takes ownership of a publication.
Related¶
- systems/emdash — first consumer on this wiki; uses atproto for its plugin registry.
- systems/workers-ai — powers the EmDash labeler moderation service on atproto.
- concepts/capability-based-sandbox — the execution-layer complement (atproto handles distribution/identity; the sandbox handles runtime authority).
- companies/cloudflare — operator of the EmDash default registry services.