Bluesky verifies your login. Mudsky never asks for your Bluesky password.
Mudsky stores your authenticated DID and character ID, along with your public handle, display name, avatar URL and biography, to populate your character profile. Handles can change; your DID keeps the same character attached to your account.
Login requests authentication only. Mudsky does not read private messages or publish, like, repost or follow on your behalf. Public profile information is fetched from Bluesky’s public service.
Login credentials and character records are encrypted on the server. Browser sessions expire after seven days; pending login requests expire after ten minutes. Sign out removes the current browser session. Character profiles remain for your next visit.
The HTTPS service keeps standard access logs. OAuth callback query parameters are omitted from those logs. Browser and SSH play share the stock game, with separate game character names, passwords and saves. A browser connection ticket expires after thirty seconds and is consumed once. The bridge does not log commands, passwords or transcripts; stock world logs and saves follow the game’s own behavior. Display preferences stay on your device. The play page loads only local scripts and does not include an analytics script.
For removal of your Mudsky character profile, contact Luke Steuber. Updated 7 October 2026.