Bluesky Security Settings Checklist

Start with the email account that can reset your Bluesky password. A strong Bluesky password does not help much if someone can open your inbox and request a reset code.

Then secure third-party access and be clear about what Bluesky publishes. Most posts, follows, likes, and blocks are public on the AT Protocol. Bluesky does not have a setting that turns a normal account into a private account.

Secure sign-in and recovery

Protect the email account first

Use a unique password for the email address attached to Bluesky. Turn on the email provider's strongest multi-factor option, preferably a passkey, security key, or authenticator app. Save its recovery codes somewhere outside the inbox.

Check that the email address in Bluesky is current and verified. Bluesky uses email for password resets and requires a verified email for some features, including video uploads.

If the inbox is compromised, change the email password and end unknown email sessions before resetting Bluesky. Otherwise an attacker may still receive the next reset message.

Turn on Bluesky's email 2FA

Bluesky's documented account-level two-factor option uses a code sent by email. It is not an authenticator-app code. Turn it on in Bluesky's account security settings, then test a fresh sign-in while you still have access to the current session.

Email 2FA makes the security of the inbox even more important. It adds a second step to Bluesky sign-in, but it does not protect an inbox that someone else can already read.

Bluesky has described OAuth as the longer-term authorization system for third-party apps. Authentication options can change, so check the current Bluesky settings rather than following an old screenshot or a guide that points to an authenticator menu that is not there.

Use a unique password and a password manager

Generate a long, unique Bluesky password with a password manager. Do not reuse the email password, a social-network password, or a passphrase you use anywhere else.

Length and uniqueness matter more than adding a predictable symbol to an old password. A password manager also removes the temptation to keep a reusable password in notes, messages, or a spreadsheet.

After changing the password, revoke app passwords you do not recognize before reconnecting any tools.

Give each third-party app its own access

Prefer OAuth when an app offers it. OAuth lets you authorize an app without typing the main Bluesky password into that app.

Some Bluesky tools still use app passwords. Create a separate app password for each tool and label it with the tool's name. Never give a third-party app your main Bluesky password.

A dedicated app password has a practical benefit: you can revoke one integration without changing the main password or breaking every other tool. Review the app-password list after you stop using a client, scheduler, or script. Revoke old entries instead of leaving them active in case you need them later.

TheBlue.social currently supports a dedicated Bluesky app password for connected-account actions. Create one for TheBlue rather than reusing an app password from another client. If you disconnect the account and no longer plan to use the integration, revoke that app password in Bluesky too.

Treat normal Bluesky posts as public

Bluesky explains that most posts, follows, likes, and blocks are public on the network. Deleting a post removes it from the account repository and Bluesky services, but screenshots, quotes, caches, or copies may remain elsewhere.

Before posting, remove information that should not be public:

  • home and work addresses
  • travel dates that reveal an empty home
  • private email addresses and phone numbers
  • tickets, documents, and screenshots containing codes or account details
  • photo metadata or visible details that reveal a location

Reply controls decide who can join a thread. They do not make the original post private. Content labels and moderation settings change how content is displayed; they are not access controls for a private audience.

Direct messages have a different access model from public posts, but they are still a poor place for passwords, recovery codes, identity documents, or payment details.

Use moderation controls for unwanted contact

Mute an account when you want to stop seeing it without creating a public block record. Block an account when you want Bluesky clients to prevent direct interaction between the accounts.

Review moderation lists before subscribing. A list reflects its creator's decisions and can change later. Check several included accounts, the list description, and the creator before applying it to your timeline.

Use thread reply controls before a conversation becomes difficult to manage. You can limit replies on a post without pretending that the post itself is private.

For harassment, impersonation, threats, or illegal content, save the URLs and other details you need, then use Bluesky's reporting tools. Do not keep engaging only to collect more screenshots.

Check identity before trusting an account

A familiar display name and avatar are easy to copy. Open the profile and check the handle, linked site, posting history, and verification details.

Bluesky offers three useful identity signals:

  • A domain handle connects the account to a domain the owner controls.
  • A standard blue verification badge indicates that Bluesky has verified an authentic and notable account.
  • A scalloped badge identifies a Trusted Verifier; opening a verification badge shows who issued it.

These signals help confirm identity. They do not prove that every post is correct or that every link from the account is safe.

For a company, government agency, newsroom, or public figure, also open the organization's own website and follow its Bluesky link. Do that before responding to a request for money, credentials, or urgent action.

Keep a recovery and review plan

Write down the recovery steps before you need them:

  1. Secure the attached email account and end unknown email sessions.
  2. Reset the Bluesky password from the official app or bsky.app.
  3. Review Bluesky app passwords; revoke anything unfamiliar.
  4. Check recent posts, follows, blocks, profile changes, and direct messages.
  5. Contact support@bsky.app if the account remains compromised or inaccessible.
  6. Tell affected contacts through a channel they already know if the account sent scams or malicious links.

Do not follow a password-reset link sent in an unexpected direct message. Open Bluesky directly and start the recovery there.

Review the checklist every few months

Record the review date so you know when each item was last checked.

  • The attached email address is current, verified, and protected with MFA.
  • Bluesky email 2FA is on.
  • The Bluesky password is unique and stored in a password manager.
  • Every third-party tool uses OAuth or its own labeled app password.
  • Old and unfamiliar app passwords are gone.
  • Profile links and verification details still point to the right domains.
  • Reply controls, muted accounts, blocks, and moderation lists still match what you want.
  • The recovery steps and support address are saved somewhere you can reach without the Bluesky account.

Frequently asked questions

Does Bluesky support authenticator-app 2FA?

Bluesky's documented account setting uses an emailed sign-in code. Bluesky has discussed adding more authentication factors as OAuth develops, but an old guide that tells you to scan an authenticator QR code is not describing that setting.

Can I make my Bluesky account private?

Normal Bluesky posts and most social-graph activity are public on the AT Protocol. Reply controls, mutes, blocks, and moderation labels change interaction or display behavior; they do not create a private-post account.

Should I give a scheduler my Bluesky password?

No. Use OAuth when the tool supports it. For a legacy integration that requires an app password, create a unique app password for that tool and revoke it when the integration is no longer needed.

What should I do after clicking a suspicious link?

Close the page, do not enter credentials, and check the destination independently. If you entered the Bluesky password or an app password, change or revoke it. If you entered email credentials, secure the email account first, then reset Bluesky and review recent account activity and app passwords.

Last updated: August 12, 2026