API guide

The Bluesky API in 2026.Free and open. Links are on you.

Bluesky's API is the AT Protocol: free, with no developer registration. You post by writing an app.bsky.feed.post record to the user's server with com.atproto.repo.createRecord, after uploading any image as a blob. Bots can sign in with an app password; Bluesky asks apps with their own login to use OAuth. Links, mentions and hashtags only work if you send their byte positions as facets.

Checked October 6, 2026. Breakreach is our product.
# 1. A session, with an app passwordcurl -X POST https://bsky.social/xrpc/com.atproto.server.createSession \  -H "Content-Type: application/json" \  -d '{"identifier": "northbeam.coffee", "password": "'$APP_PASSWORD'"}' # 2. The image, uploaded as a blob (2 MB at most)curl -X POST "$PDS/xrpc/com.atproto.repo.uploadBlob" \  -H "Authorization: Bearer $ACCESS_JWT" \  -H "Content-Type: image/jpeg" \  --data-binary @launch.jpg # 3. The post record, with the blob as an embedcurl -X POST "$PDS/xrpc/com.atproto.repo.createRecord" \  -H "Authorization: Bearer $ACCESS_JWT" \  -H "Content-Type: application/json" \  -d '{    "repo": "'$DID'", "collection": "app.bsky.feed.post",    "record": {"$type": "app.bsky.feed.post",      "text": "Morning Light is out tomorrow.",      "createdAt": "2026-10-07T07:00:00Z",      "embed": {"$type": "app.bsky.embed.images", "images": [        {"alt": "A bag of Morning Light", "image": '$BLOB'}]}}  }'
1/3 POST com.atproto.server.createSessionSending
Published · now
northbeam.coffee· now

Morning Light is out tomorrow. Honey, orange and cocoa, our lightest roast yet.

The Bluesky API at a glanceWhat it takes before the first post.

Price
Free. No paid tier and no developer registration
Sign-in
An app password for bots and scripts; OAuth for apps where people log in, per Bluesky
Posting
com.atproto.repo.createRecord on the user's server, after uploadBlob for media
Rate limit
5,000 points an hour and 35,000 a day per account; a post costs 3
Text
300 graphemes, and 3,000 bytes
Images
Up to 10 with the gallery embed (June 2026), or 4 with the images embed, 2 MB each
Links and mentions
Not detected: you send facets with UTF-8 byte offsets
Scheduling
None: a future createdAt doesn't schedule a post

Checked on October 6, 2026, from Bluesky's developer documentation and terms.

Our recommendation

To post to Bluesky from your product, use Breakreach's API.We built it, so here's the case.

See the request
  • OAuth done for you: people sign in on Bluesky's own page, with no app password to create or paste
  • Up to 10 photos in one request, recompressed under 2 MB when needed, or a video of up to 10 minutes
  • Scheduling Bluesky doesn't have, and the same request posts to X, Threads and the rest

When to use Bluesky's API directly. Breakreach sends your text as is, without facets, so links, mentions and hashtags aren't clickable yet, and it doesn't post threads or alt text. The AT Protocol is free and open, so build those on it directly if you need them.

How to get access to the Bluesky APIFrom a developer account to your first real post.

  1. 1Pick the sign-inFor a bot or a script on your own account, an app password from Bluesky's settings. For an app where people log in, OAuth, which Bluesky asks such apps to use.
  2. 2For OAuth, publish your client metadataYour client_id is the https URL of a JSON document describing the client. The flow requires PKCE, DPoP with server nonces, pushed authorization requests, and the atproto scope.
  3. 3Find the user's serverWrites go to the user's PDS, which you resolve as part of creating the session; bsky.social works as the entry point.
  4. 4Follow the developer guidelinesNo spam, and no automated or bulk interactions.

There's no registration, approval or API key. With password sessions, reuse them: createSession is limited to 30 calls per 5 minutes and 300 a day per account.

How to post with the Bluesky APIThe requests in the demo above, one by one.

  1. 1Create a sessioncom.atproto.server.createSession with the handle and app password returns accessJwt, refreshJwt and the DID. With OAuth, tokens come from the user's authorization server instead.
  2. 2Upload the mediacom.atproto.repo.uploadBlob with the image bytes returns a blob. Strip EXIF first: Bluesky recommends it. A blob nothing references is deleted after a few minutes.
  3. 3Create the recordcom.atproto.repo.createRecord with collection app.bsky.feed.post: text, createdAt, and an embed: app.bsky.embed.images, the gallery embed for 5 to 10 photos, or app.bsky.embed.video.

To make a link, mention or hashtag clickable, add a facet with its UTF-8 byte start and end, and a #link, #mention (with a DID) or #tag feature. Videos are better sent through video.bsky.app and its job status, so the post doesn't appear before the video is processed.

Common Bluesky API errorsWhat they mean and how to fix them.

ErrorWhat it meansFix
429 RateLimitExceededThe points budget, the per-IP limit, or too many createSession calls.Back off, and reuse sessions.
400 ExpiredTokenThe accessJwt expired.Call refreshSession with the refreshJwt.
401 AuthenticationRequiredWrong handle or password.Check the handle, and use an app password.
400 InvalidRequestOver 300 graphemes, an image over 2 MB, or more than 4 images in embed.images.Validate first; use the gallery embed for 5 to 10 photos.
413 PayloadTooLargeA blob over the server's 50 MB cap.Send video through video.bsky.app.
BlobNotFoundThe blob expired before a record referenced it.Upload it again right before createRecord.

Bluesky API limitsRate limits, text and media.

  • Writes5,000 points an hour and 35,000 a day per account: a create costs 3, an update 2, a delete 1, so at most 1,666 posts an hour.
  • Requests3,000 per 5 minutes per IP on the PDS; createSession 30 per 5 minutes and 300 a day per account. Over a limit: 429.
  • Text300 graphemes and 3,000 bytes. An emoji is one grapheme.
  • Images2 MB each. 4 per post with app.bsky.embed.images, 10 with the gallery embed added in June 2026, which requires alt text and an aspect ratio.
  • VideoMP4 up to 300 MB; Bluesky announced 10-minute videos in August 2026. Accounts need a verified email to upload video, and daily video limits apply.

Is the Bluesky API free?

Yes. The AT Protocol has no paid tier and no developer registration, and Bluesky's docs mention no pricing.

What costs is the work: sessions or OAuth with DPoP, blobs, a facet for every link, and a server to resolve for each user.

Through Breakreach, a Bluesky account counts like any other connected account: the first 2 are free, then $5 a month each up to 20.

Ways to post to Bluesky from code

What you set upPricePosts to Bluesky
BreakreachAn API key. Accounts connect through Breakreach's reviewed apps, or your users connect theirs on a hosted pageFirst 2 accounts free, then $5 a month per account (less from 21)Yes, Up to 10 photos
Bluesky's own APIAn app password, or OAuth with DPoPFreeYes
Upload-PostAn API keyFree for 2 profiles and 10 uploads a month; Basic $24 a month for 5 profilesYes
ZernioAn API keyFirst 2 accounts free, then $6 per account up to 10, $3 up to 100, $1 afterYes
AyrshareAn API keyFrom $149 a month for 1 profile, no free planYes
OutstandAn API key$19 a month for 3,000 posts, then per postYes
Checked on October 6, 2026, from Bluesky's developer documentation and each company's pricing page. Breakreach is our product.

What the Bluesky API can't do

  • Schedule: a future createdAt doesn't schedule a post
  • Detect links, mentions and hashtags: you send facets
  • Build link cards: you fetch the page and upload the thumbnail yourself
  • Report views

Post to Bluesky with Breakreach's APIOne request, scheduled, with retries.

POST /v1/posts
curl https://api.breakreach.com/v1/posts \  -H "Authorization: Bearer $BREAKREACH_API_KEY" \  -H "Content-Type: application/json" \  -d '{    "content": "Morning Light is out tomorrow. Honey, orange and cocoa, our lightest roast yet.",    "accountIds": ["6701a2f4c9e84b0012a3b4ce"],    "media": ["https://cdn.northbeam.coffee/launch.jpg"],    "scheduledAt": "2026-10-07T09:00:00"  }'

What it posts on Bluesky

  • Text postsUp to 300 characters, counted as Bluesky counts them; longer text is cut at 300.
  • PhotosUp to 10 per post. One over 2 MB or 4,000 pixels a side is recompressed to fit.
  • VideoOne video of up to 10 minutes and 300 MB.
  • StatsLikes, replies and reposts per post, followers and post count.

Not yet

  • Clickable links, mentions and hashtags
  • Threads, link cards and alt text

The full reference, webhooks and the price per connected account are on the developers page, and the OpenAPI spec is at api.breakreach.com/v1/openapi.json.

FAQ

Questions, answered.

Short answers about the Bluesky API.

Yes. The AT Protocol has no paid tier and no developer registration. Rate limits apply per account: 5,000 points an hour, a post costing 3.

There isn't one. A bot signs in with the account's handle and an app password; an app where people log in uses OAuth, with a client metadata document as its client_id.

Bluesky's guidance: apps with their own login should use OAuth; single-purpose bots and command-line tools may use app passwords.

4 with app.bsky.embed.images, and up to 10 with the gallery embed added in June 2026. Each image is up to 2 MB.

Add a facet: the link's UTF-8 byte start and end in the text, and an app.bsky.richtext.facet#link feature with the URI. Bluesky doesn't detect links on its own.

No: createdAt is set by the client, and a date in the future doesn't schedule anything. Scheduling means your own job, or an API like Breakreach.

The first 2 connected accounts are free; from the third it's $5 a month per account up to 20, $3 up to 100, then $2. You pay per connected account, never per post or per request.

Instagram
TikTok
LinkedIn
YouTube
X
Facebook
Threads

Put your socials on autopilot.Live in two minutes.

Plans from $29 a month. Cancel anytime.