Tour the Atmosphere. Switch clients, share universal links, browse any PDS.

Granular OAuth scope picker (replaces transition:generic) master

Two-step sign-in flow: after entering a handle, the user picks which write-side permissions to grant (create / update / delete / blob upload) — all checked by default. The runtime scope passed to client.signIn() is built from the selection, replacing the broad transition:generic legacy scope. The metadata endpoint advertises the superset of granular scopes so any subset the user picks is valid under PAR. Reads stay implicit since records in the user's own repo are public. Modeled on pdsls.dev's flow. https://claude.ai/code/session_017YxfAzFqAcWiafJkQ5gAfk


+455 -95
8 changed files