How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Bluesky Administration API

Administrative operations for managing accounts and invites.

Bluesky Administration API is one of 24 APIs that Bluesky publishes on the APIs.io network, described by a machine-readable OpenAPI specification and an AsyncAPI event-driven specification.

Tagged areas include Administration. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, an API reference, authentication docs, rate-limit docs, and an AsyncAPI specification.

This API exposes 14 operations across 14 paths, and defines 8 schemas. It is described by OpenAPI 3.1.0, at version 1.0.0.

Requests are made against 2 base URLs: https://bsky.social/xrpc, https://public.api.bsky.app/xrpc.

14 operations 14 paths 8 schemas 5 GET9 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.1.0
API Version
1.0.0
Servers
https://bsky.social/xrpc
https://public.api.bsky.app/xrpc
Authentication
HTTP Bearer
License
Resource Areas
1

Authentication & Security 1

Bluesky Administration API declares 1 security scheme for authenticating requests. It accepts HTTP bearer tokens (Bearer).

Paths & Operations 14

Across 14 paths, the API surfaces 14 operations — 5 GET, 9 POST. Each is listed below with its method, path, parameters, and response codes.

Administration 14

Administrative operations for managing accounts and invites.

POST
/xrpc/com.atproto.admin.deleteAccount
Bluesky Delete a user account as an administrator.
adminDeleteAccount body → 200400401
POST
/xrpc/com.atproto.admin.disableAccountInvites
Bluesky Disable an account from receiving new invite codes, but does not invalidate existing codes.
adminDisableAccountInvites body → 200400401
POST
/xrpc/com.atproto.admin.disableInviteCodes
Bluesky Disable some set of codes and/or all codes associated with a set of users.
adminDisableInviteCodes body → 200400401
POST
/xrpc/com.atproto.admin.enableAccountInvites
Bluesky Re-enable an account's ability to receive invite codes.
adminEnableAccountInvites body → 200400401
GET
/xrpc/com.atproto.admin.getAccountInfo
Bluesky Get details about an account.
adminGetAccountInfo 1 param → 200400401
GET
/xrpc/com.atproto.admin.getAccountInfos
Bluesky Get details about some accounts.
adminGetAccountInfos 1 param → 200400401
GET
/xrpc/com.atproto.admin.getInviteCodes
Bluesky Get an admin view of invite codes.
adminGetInviteCodes 3 params → 200400401
GET
/xrpc/com.atproto.admin.getSubjectStatus
Bluesky Get the service-specific admin status of a subject (account, record, or blob).
adminGetSubjectStatus 3 params → 200400401
GET
/xrpc/com.atproto.admin.searchAccounts
Bluesky Get list of accounts that matches your search query.
adminSearchAccounts 3 params → 200400401
POST
/xrpc/com.atproto.admin.sendEmail
Bluesky Send email to a user's account email address.
adminSendEmail body → 200400401
POST
/xrpc/com.atproto.admin.updateAccountEmail
Bluesky Administrative action to update an account's email.
adminUpdateAccountEmail body → 200400401
POST
/xrpc/com.atproto.admin.updateAccountHandle
Bluesky Administrative action to update an account's handle.
adminUpdateAccountHandle body → 200400401
POST
/xrpc/com.atproto.admin.updateAccountPassword
Bluesky Update the password for a user account as an administrator.
adminUpdateAccountPassword body → 200400401
POST
/xrpc/com.atproto.admin.updateSubjectStatus
Bluesky Update the service-specific admin status of a subject (account, record, or blob).
adminUpdateSubjectStatus body → 200400401

Schemas 8

The contract defines 8 schemas that model the data the API accepts and returns. The most detailed are ComAtprotoAdminDefsAccountView (12 properties), ComAtprotoServerDefsInviteCode (7 properties), ComAtprotoAdminDefsRepoBlobRef (3 properties), ComAtprotoServerDefsInviteCodeUse (2 properties). Each schema is shown below with its type and property counts.

ComAtprotoAdminDefsAccountView
object
12 properties 3 required
ComAtprotoAdminDefsRepoBlobRef
object
3 properties 2 required
ComAtprotoRepoStrongRef
object
2 properties 2 required
ComAtprotoServerDefsInviteCode
object
7 properties 7 required
ComAtprotoAdminDefsRepoRef
object
1 property 1 required
ComAtprotoAdminDefsThreatSignature
object
2 properties 2 required
ComAtprotoServerDefsInviteCodeUse
object
2 properties 2 required
ComAtprotoAdminDefsStatusAttr
object
2 properties 1 required

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

bluesky-administration-api-openapi.yml Raw ↑

Other APIs Bluesky publishes across the network.

Bluesky Jetstream
Bluesky Actor Profiles API
Bluesky Chat Actors API
Bluesky Chat Moderation API
Bluesky Content Labels API
Bluesky Conversations API
Bluesky Feeds API
Bluesky Identity API
Bluesky Labels API
Bluesky Moderation API
Bluesky Notifications API
Bluesky Ozone Communication API
Where this information came from

This is an independent, third-party profile of Bluesky Administration API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.