From 349bd79624cabd1819ca8895fa416fbaaa0d3ec9 Mon Sep 17 00:00:00 2001 From: "@permadeath.com" Date: Wed, 9 Sep 2026 14:55:02 -0400 Subject: [PATCH] docs: uploadBlob is authenticated by the agent token Co-Authored-By: Claude Fable 5.1 Change-Id: I84d71a033a53ec5a7c69826252309c5b2a0cf4f5 --- docs/running-locally.md | 8 +++----- 1 file changed, 3 insertions(+), 5 deletions(-) diff --git a/docs/running-locally.md b/docs/running-locally.md index 3b77bfa3..c51b7b23 100644 --- a/docs/running-locally.md +++ b/docs/running-locally.md @@ -724,15 +724,13 @@ reference a record puts in a field: ```sh curl -s -X POST localhost:3000/xrpc/com.atproto.repo.uploadBlob \ -H 'content-type: image/png' \ - -H "didbot-repo: $did" \ + -H "authorization: Bearer $TOKEN" \ --data-binary @some.png | jq # {"blob":{"$type":"blob","ref":{"$link":"bafkrei…"},"mimeType":"image/png","size":2852}} ``` -The `didbot-repo` header is which account the blob is for. -`com.atproto.repo.uploadBlob` takes no parameters, because in atproto the -account comes from the request's authentication and this server has none yet; -It is a header rather than a query parameter. +`com.atproto.repo.uploadBlob` takes no parameters: the agent token is which +account the blob is for. The CID in that reference is the sha-256 of the bytes, so it can be checked without trusting this server: -- 2.51.2