Authenticated Transfer B. Newbold Internet-Draft Bluesky Social Intended status: Standards Track 1 October 2026 Expires: 4 April 2027 The "at" URI Scheme draft-newbold-atp-aturi-00 Abstract This document defines the "at" URI scheme, which is used to reference accounts and data records in the Authenticated Transfer Protocol. About This Document This note is to be removed before publishing as an RFC. Status information for this document may be found at https://datatracker.ietf.org/doc/draft-newbold-atp-aturi/. Discussion of this document takes place on the Authenticated Transfer Working Group mailing list (mailto:atp@ietf.org), which is archived at https://mailarchive.ietf.org/arch/browse/atp/. Subscribe at https://www.ietf.org/mailman/listinfo/atp/. Source for this draft and an issue tracker can be found at https://github.com/ietf-wg-atp/drafts. Status of This Memo This Internet-Draft is submitted in full conformance with the provisions of BCP 78 and BCP 79. Internet-Drafts are working documents of the Internet Engineering Task Force (IETF). Note that other groups may also distribute working documents as Internet-Drafts. The list of current Internet- Drafts is at https://datatracker.ietf.org/drafts/current/. Internet-Drafts are draft documents valid for a maximum of six months and may be updated, replaced, or obsoleted by other documents at any time. It is inappropriate to use Internet-Drafts as reference material or to cite them other than as "work in progress." This Internet-Draft will expire on 4 April 2027. Newbold Expires 4 April 2027 [Page 1] Internet-Draft AT URI October 2026 Copyright Notice Copyright (c) 2026 IETF Trust and the persons identified as the document authors. All rights reserved. This document is subject to BCP 78 and the IETF Trust's Legal Provisions Relating to IETF Documents (https://trustee.ietf.org/ license-info) in effect on the date of publication of this document. Please review these documents carefully, as they describe your rights and restrictions with respect to this document. Code Components extracted from this document must include Revised BSD License text as described in Section 4.e of the Trust Legal Provisions and are provided without warranty as described in the Revised BSD License. Table of Contents 1. Introduction . . . . . . . . . . . . . . . . . . . . . . . . 2 2. Structure . . . . . . . . . . . . . . . . . . . . . . . . . . 3 3. Syntax . . . . . . . . . . . . . . . . . . . . . . . . . . . 4 3.1. Record References . . . . . . . . . . . . . . . . . . . . 5 4. Examples . . . . . . . . . . . . . . . . . . . . . . . . . . 5 5. Security Considerations . . . . . . . . . . . . . . . . . . . 7 6. IANA Considerations . . . . . . . . . . . . . . . . . . . . . 7 6.1. URI Scheme Registration . . . . . . . . . . . . . . . . . 7 7. References . . . . . . . . . . . . . . . . . . . . . . . . . 7 7.1. Normative References . . . . . . . . . . . . . . . . . . 7 7.2. Informative References . . . . . . . . . . . . . . . . . 7 Acknowledgments . . . . . . . . . . . . . . . . . . . . . . . . . 8 Author's Address . . . . . . . . . . . . . . . . . . . . . . . . 8 1. Introduction The Authenticated Transfer Protocol enables the creation of decentralized networks for publication of self-certifying data. An introduction to the overall protocol architecture is given in [AT-ARCH], and the data repository and synchronization mechanisms are described in [AT-REPOSYNC]. Each account has a global permanent account identifier that can be resolved to a network hosting location and to public key material. Multiple account identifier systems are supported, but details are out of scope for this document. Accounts publish structured data records of different application-defined types in data repositories. Each account has a single repository for all of its public data records, organized in collections by record type, with one or more records in each collection. Newbold Expires 4 April 2027 [Page 2] Internet-Draft AT URI October 2026 Individual records can be globally referenced by account, collection, and record key. Records themselves may include references to other records, forming a global data graph. Record references can be resolved to fetch individual records. They can also be used when annotating records for the purpose of content moderation. This document describes a string identifier syntax for referencing data records and entire accounts. The identifiers described in this version of the document comply with most of the [RFC3986] generic Uniform Resource Identifier (URI) requirements, but not all of them. Using account identifiers with multiple colons in the authority section violates the generic syntax rules for URI schemes using the double-slash prefix (//), which this version uses. This means the identifier syntax described in this document is not eligible for permanent registration in the IANA URI Registry under [RFC7595]. 2. Structure The generic structure of an "at" URI is: "at://" ACCOUNT-AUTHORITY [ PATH ] [ "?" QUERY ] [ "#" FRAGMENT ] The required authority section references an account. It may be a permanent account identifier or an account handle. A URI that only includes the authority section can be used as a reference to an overall account. Handles in the authority section are discouraged in most other use cases; see Section 5. Except for the authority syntax noted in Section 1, the structure aligns with the generic structure and semantics described in Section 3 of [RFC3986]. An empty authority section is not allowed. Userinfo is not supported in the authority section, and host/port separation with a colon character is not used. The query and fragment sections have no defined semantics and are reserved for future use. The path section can be used to reference a specific resource controlled by the account authority. A common use case is to reference an individual data record from the account's public data repository: "at://" ACCOUNT-AUTHORITY "/" COLLECTION "/" RECORD-KEY Newbold Expires 4 April 2027 [Page 3] Internet-Draft AT URI October 2026 The collection part indicates the data record type (schema), and the record key identifies the individual record. The URI path section matches the path under which records are stored in the repository data structure described in [AT-REPOSYNC]. 3. Syntax The overall AT URI encoded string length limit is 8192 ASCII characters. AT URIs MUST NOT include a trailing slash. The authority section of AT URIs can contain either a permanent account identifier or an account handle. The syntax of specific account identifier systems is out of scope for this document, but a few generic syntax restrictions apply to all such identifiers: * the account identifier string is ASCII, containing letters (A-Z, a-z), digits (0-9), period (.), hyphen (-), underscore (_), and colon (:) * other ASCII characters may be represented with percent encoding (percent character % followed by two hexadecimal characters) * must not end in a colon (:) * length (including percent encoding) is between 1 and 2048 characters * MUST NOT be a simple account handle The account handle system is out of scope for this document, but the handle syntax is as follows: * at most 253 ASCII characters in total * consists of multiple segments separated by periods (.) * empty segments and leading or trailing periods are not allowed * there must be at least two segments, and thus at least one period ("bare" top-level domains are not allowed) * each segment must have between 1 and 63 characters, consisting of lower-case letters (a-z), digits (0-9), and hyphens (-) * segments cannot begin or end with hyphens * the last segment must not start with a digit Newbold Expires 4 April 2027 [Page 4] Internet-Draft AT URI October 2026 Handles MUST be normalized to lower-case when included in AT URIs. 3.1. Record References An AT URI referencing a record has additional syntax restrictions. It has exactly two path segments, and must not include query parameters. The first path component must be a valid Namespace Identifier (NSID) string, as defined in Appendix D of [AT-REPOSYNC]. A non-normative summary of that syntax is: * at most 317 ASCII characters in length * overall NSID is case-sensitive * "domain authority" part (reverse-order DNS hostname, with at least two segments separated by periods) separated from a final "name" part by a period (.) * domain authority segments are each between 1 and 63 characters; consist of ASCII lower-case letters (a-z), digits (0-9), and hyphens (-); must not start or end with a hyphen; the first segment must not start with a digit * the final name part is between 1 and 63 characters; consists of ASCII alphanumerics (A-Z, a-z, 0-9); must not start with a digit The second path component is a Record Key string, with syntax defined in Section 3.1 of [AT-REPOSYNC]. A non-normative summary of that syntax is: * length between 1 and 512 ASCII characters * consists of alphanumerics (A-Z, a-z, 0-9), period (.), hyphen (-), underscore (_), colon (:), and tilde (~) * case-sensitive * literal values . and .. are forbidden 4. Examples The following are valid AT URIs referencing accounts: at://did:plc:foxkcdp2jhdxd75z7uuqu3s2 at://handle.example.com Newbold Expires 4 April 2027 [Page 5] Internet-Draft AT URI October 2026 The following are invalid AT URIs under the syntax defined in this document: // trailing slash at://did:plc:foxkcdp2jhdxd75z7uuqu3s2/ // userinfo at://user:pass@did:plc:foxkcdp2jhdxd75z7uuqu3s2 // @-sign at://@handle.example.com The following are valid AT URIs referencing a record: at://did:plc:foxkcdp2jhdxd75z7uuqu3s2/com.example.record/3mwp2ezf3fh22 at://did:plc:foxkcdp2jhdxd75z7uuqu3s2/com.example.more-sections.record/3mwp2ezf3fh22 at://did:plc:foxkcdp2jhdxd75z7uuqu3s2/com.example.otherRecordV2/3mwp2ezf3fh22 at://did:plc:foxkcdp2jhdxd75z7uuqu3s2/com.example.record/... at://did:plc:foxkcdp2jhdxd75z7uuqu3s2/com.example.record/~home at://did:plc:foxkcdp2jhdxd75z7uuqu3s2/com.example.r/1 The following are invalid record references (though they may be valid generic AT URIs): // disallowed record keys at://did:plc:foxkcdp2jhdxd75z7uuqu3s2/com.example.record/.. at://did:plc:foxkcdp2jhdxd75z7uuqu3s2/com.example.record/one@two // disallowed NSIDs at://did:plc:foxkcdp2jhdxd75z7uuqu3s2/example/3mwp2ezf3fh22 at://did:plc:foxkcdp2jhdxd75z7uuqu3s2/com.example/3mwp2ezf3fh22 at://did:plc:foxkcdp2jhdxd75z7uuqu3s2/com.EXAMPLE.record/3mwp2ezf3fh22 at://did:plc:foxkcdp2jhdxd75z7uuqu3s2/123.example.record/3mwp2ezf3fh22 at://did:plc:foxkcdp2jhdxd75z7uuqu3s2/com.example.bad-record/3mwp2ezf3fh22 at://did:plc:foxkcdp2jhdxd75z7uuqu3s2/com.example.record-/3mwp2ezf3fh22 // trailing slash at://did:plc:foxkcdp2jhdxd75z7uuqu3s2/com.example.record/3mwp2ezf3fh22/ // query section at://did:plc:foxkcdp2jhdxd75z7uuqu3s2/com.example.record/3mwp2ezf3fh22?key=value Newbold Expires 4 April 2027 [Page 6] Internet-Draft AT URI October 2026 5. Security Considerations Record references that use account handles instead of permanent account identifiers can have the authority of the reference change over time. Such references should be resolved to a permanent account identifier before being persisted to long-term storage. References stored in record data should always use permanent account identifiers. 6. IANA Considerations 6.1. URI Scheme Registration As noted in Section 1, the identifier syntax described in this version of the document is not eligible for permanent registration in the IANA URI Registry under [RFC7595]. If it were, registration metadata would be included in this section. 7. References 7.1. Normative References [AT-REPOSYNC] Holmgren, D. and B. Newbold, "Authenticated Transfer: Repository and Synchronization", September 2026, . [RFC3986] Berners-Lee, T., Fielding, R., and L. Masinter, "Uniform Resource Identifier (URI): Generic Syntax", STD 66, RFC 3986, DOI 10.17487/RFC3986, January 2005, . [RFC7595] Thaler, D., Ed., Hansen, T., and T. Hardie, "Guidelines and Registration Procedures for URI Schemes", BCP 35, RFC 7595, DOI 10.17487/RFC7595, June 2015, . 7.2. Informative References [AT-ARCH] Newbold, B. and D. Holmgren, "Authenticated Transfer: Architecture Overview", March 2026, . Newbold Expires 4 April 2027 [Page 7] Internet-Draft AT URI October 2026 [ATPAPER] Kleppmann, M., Frazee, P., Gold, J., Graber, J., Holmgren, D., Ivy, D., Johnson, J., Newbold, B., and J. Volpert, "Bluesky and the AT Protocol: Usable Decentralized Social Media", December 2024, . Acknowledgments This document is based on the original Authenticated Transfer URI design work by Paul Frazee and Daniel Holmgren, as described in [ATPAPER]. Author's Address Bryan Newbold Bluesky Social Email: bnewbold@robocracy.org Newbold Expires 4 April 2027 [Page 8]