I declare my position at the outset: Kripties has been designated by Eurosky as a trusted verifier on mu.social for art and culture accounts in Spanish. Eurosky has not reviewed this article and bears no responsibility for my statements, including any criticisms. I write from within; for this reason, I have taken special care not to promote a model in which I believe.
My intention is to explain an architecture, as it is difficult to comprehend if one has only utilised networks where everything is welded together. On Instagram or X, a single company simultaneously controls your identity, the server where your data resides, the application through which you view it, the algorithm that orders what you read, and the rules that determine what may be published. These are five distinct elements managed by the same corporation. When you depart, you retain nothing: you commence from zero.
The origins of Bluesky
In December 2019, Jack Dorsey, then at the helm of Twitter, announced that the company would fund a small, independent team to develop an open and decentralised standard for social networks. The idea, in his own words, was for Twitter to eventually become a client of that standard, not its owner. This was not a reaction to Musk’s acquisition, which occurred three years later: it predates it.
That team was established as an independent company at the end of 2021 and is today called Bluesky Social PBC. It is necessary to clarify its legal nature, as it is often misinterpreted: it is a private company, with investment and a requirement to be profitable, constituted in a form that allows it to incorporate a public mission into its decisions. It is not a foundation or a non-profit organisation. The application opened in beta by invitation in February 2023 and to the general public on 6 February 2024, with approximately three million accounts. Today, it reports over forty million.
The problem it claimed to resolve is one we have all endured: that your identity, your history and your relationships are the property of the platform, and that changing services necessitates the loss of everything.
What is the protocol
The solution it proposes is named the AT Protocol, or Authenticated Transfer Protocol, and consists of separating into independent components what was previously unified. It is worth understanding these components, as everything else derives from them.
Your identity is a stable identifier called a DID. It is not your username, which may change, but a permanent code that represents you across the entire network and allows for the cryptographic verification that your posts are yours.
Your data resides on a server called a PDS, or Personal Data Server, which hosts your posts, your followers, your lists and the keys with which they are signed. This may be the one provided by Bluesky, another provider, or one of your own.
Then there are two components that are rarely visible but perform the heavy lifting: the relays, which collect updates from thousands of servers and distribute them, and the AppViews, which index all of this to enable search functionality, counters and conversation threads.
Finally, there is the client, which is the application you use to access the service, and the moderation services, which publish labels that a client may or may not choose to apply.
The consequence is that each component may have a different operator. You may store your data on a European server, access it via an application developed by a different organisation, view content ordered by a third-party algorithm and apply moderation rules from a fourth. Should you tire of your hosting provider, you may migrate while retaining your identity and your followers.
What is frequently omitted
All of the above is accurate and is not mere marketing, yet it is not the perfect decentralisation sometimes described. The reality is more uneven, and those who participate in this should acknowledge it.
Setting up your own data server is viable, and some individuals do so: by the end of 2024, with nearly twenty-six million users on the network, just over four thousand were operating their own infrastructure. However, setting up a relay is bandwidth-intensive, and setting up an AppView—that is, the machinery that indexes and searches the entire network—is resource-intensive to the point that today almost everyone depends on those already in existence. The official documentation acknowledges this without embellishment. Thus, identity and hosting are reasonably distributed, while discovery and large-scale moderation remain quite concentrated.
There is one further dependency, technical but significant: the global directory that dictates where each identity resides was created and operated by Bluesky. In 2025, the company announced the creation of an independent organisation in Switzerland to assume this function, which is a step in the right direction while simultaneously demonstrating that identity was not born as separate from the company as the discourse suggested.
The origins of Eurosky
Here, the European element enters. Eurosky is a programme of Stichting Modal, a Dutch non-profit foundation that aims to build social infrastructure hosted in Europe and subject to European law. It has been operational since the end of 2025 and offers three components: a European data server, a portal to manage your account, and a client, which is mu.
The distinction from Bluesky lies not in the protocol, which is identical, but in who hosts the data and under which jurisdiction. If your account resides on the Eurosky server, your data is in Europe, the data controller is a Dutch foundation and your rights are exercised against a European entity subject to data protection regulations, rather than a United States corporation.
A further honest caveat: this does not imply that everything you publish remains in Europe. The protocol is designed so that public content is replicated by relays and indices worldwide. Sovereignty refers to your origin provider and your legal relationship with them, not to the notion that every copy of every message remains on the continent.
What is mu.social
Mu is a client, that is, an application for reading, posting, and following conversations, launched on 11 June 2026. Today, it is used via a browser; the iOS application is in beta, available through TestFlight, and the Android version will follow. Its code is a public fork of the Bluesky client, which means it starts from a common base and adds its own features and policies on top.
The point of interest is how it relates to the rest. You may access mu with an account you already possess on Bluesky: your identity, your posts and your followers remain where they were, and mu is merely the window through which you view them. Changing clients does not relocate your data. Should you create a new account via mu, that account is hosted on the Eurosky server, though it remains visible from Bluesky.
Regarding moderation, mu has its own rules, is restricted to adults, and here is the necessary honesty again: for the moment, it applies by default the moderation labels published by Bluesky and explains why with a candour I appreciate: operating a complete trust and safety infrastructure at scale requires financial and human resources it does not yet possess. Its own layer was announced for the summer of 2026, and I have been unable to confirm the extent to which it is currently operational.
There is also a structural limitation that its own policy explains clearly: a client may decide what to display, hide content and apply labels, but it cannot delete from an external server what it does not host. When content resides on another's server, they state, we may act at the mu layer but not at the hosting layer, as it is not under our control.
Blacksky, or the proof that components truly are separable
The most compelling evidence that this architecture is not merely theoretical is Blacksky, a project spearheaded by Rudy Fraser, which has developed its own comprehensive infrastructure: its data server, relay, web client, and a moderation service with guidelines determined by the community—independent of those of Bluesky—and even an alternative implementation of the protocol.
An account hosted on Blacksky maintains its identity and data within Blacksky's infrastructure, governed by Blacksky's rules, yet remains accessible from other clients due to protocol compatibility. This is the fundamental premise: identity, hosting, application, and moderation held by distinct entities, operating in unison. I should note, to avoid unsubstantiated attribution, that the compatibility of mu with Blacksky accounts is inferred from the fact that mu accepts accounts from external servers and Blacksky operates one; I have not encountered an explicit statement from mu confirming this.
What it means to be a verifier
In mu, verification is neither purchased nor contingent upon submitting identity documentation to the platform. It is predicated on social proof: trusted organisations attest that an account is authentic within their specific domain of expertise. Kripties Foundation is one such organisation, focusing on the fields of art and culture in Spanish.
The mark signifies only one thing: that the account is authentic. It does not imply that the account holder speaks the truth, that Eurosky endorses their opinions, or that the individual possesses authority over any subject matter.
Regarding the caveats, which as an interested party I must address: distributing verification among organisations does not eliminate central authority. Eurosky designs the programme, accredits the verifiers, defines the display of the mark, and retains the power to revoke it. This is delegated verification within a framework governed by Eurosky, not decentralised verification. Furthermore, a significant issue remains, which they openly acknowledge: this system functions for those belonging to a recognisable organisation, yet for those who do not, a solution has yet to be devised. The second layer intended to resolve this, based on network-derived signals, is admitted to be an unsolved challenge.
Compared to commercial models, the contrast is clear. X linked its badge to a subscription from the end of 2022 and removed the legacy ones in April 2023. Meta Verified is also a subscription, with verification via official documentation. Here, there is no payment or document: there is someone who vouches for you.
How to migrate, should you wish to
If, following this, you are interested in hosting your account in Europe, Eurosky has developed a tool named EU-HAUL. It transfers your Bluesky account from one server to another while preserving your identity, posts, photographs, followers, and settings. It does not alter your username or your list of followed accounts: it merely changes the location where your data resides.
You will require your Bluesky identifier, your login password—not an application password—access to the email address linked to the account, and the destination server address, which for Eurosky is eurosky.social.
The procedure is as follows. First, access EU-HAUL using your current identifier and password, along with the two-factor authentication code if enabled; the password is used solely to establish a temporary session. Second, verify the email address linked to your account, where you will receive the necessary codes. Third, select the destination server, which is pre-selected. Fourth, determine your new identifier: one hosted on Eurosky, a custom domain if you possess one, or retain your current one if available. Fifth, review the data, accept the terms, and initiate the migration. Retain the status page that appears, as it is the only method to monitor the process, and enter the verification code received via email there.
From that point, the transfer proceeds automatically, indicated by a progress bar: the account is created, and posts, likes, followers, blocks, and lists are imported, while photos, videos, and preferences are transferred. If you have a substantial volume of material, the media transfer may require additional time. It is not necessary to keep the page open.
The decisive step occurs at the conclusion: a PLC token. You will receive a code via email that authorises the final movement, which updates the global directory so that the entire network is informed of your account's new location. Copy this code, paste it into the status page, and submit. If it does not arrive, check your spam folder or request another from the same page.
Upon completion, two points are of importance. First: you may be presented with a recovery key, also referred to as a rotation key. Copy and store this in a secure location, as it serves as the master key for your account and cannot be retrieved subsequently. Second: to access the Bluesky application with your account now hosted on Eurosky, you must specify the hosting provider. If prompted to reactivate the account, select cancel and do not press reactivate; on the login screen, edit the provider field, select the custom option, enter eurosky.social, and log in with your credentials. This process must be repeated each time.
Your previous account is deactivated automatically. You may migrate again whenever you choose, to Bluesky or any other provider, by initiating a new migration. Ultimately, this is what distinguishes this architecture: the exit door exists and is functional.
On the open conversation
This article explains, for those unfamiliar with it, the architecture of the AT Protocol and the roles of Bluesky, Eurosky, mu.social, and Blacksky, concluding with the steps to migrate an account to a European server. I must declare my position: the foundation I chair acts as a trusted verifier for Eurosky on mu for art and culture accounts in Spanish, and Eurosky has not reviewed this text. Precisely for this reason, I have included what is often omitted: that decentralisation is asymmetric—identity and hosting are portable, but indexing and moderation at scale remain concentrated—that mu currently applies Bluesky’s moderation labels, that hosting data in Europe does not prevent its replication elsewhere, and that verification by organisations leaves the case of those who do not belong to any such group unresolved. If anyone wishes to intervene from the perspectives of protocol engineering, platform governance, or data protection, this notebook remains open.
Sources
Bluesky and AT Protocol: announcement by Jack Dorsey (December 2019); "Announcing Bluesky PBLLC" (7 February 2022); public opening on 6 February 2024; appointment of Toni Schneider as CEO (10 July 2026). Specification and documentation of the Authenticated Transfer Protocol (PDS, DID, relays, AppViews, feed generators, labelers), including warnings regarding the cost of operating relays and AppViews.
Eurosky and mu: terms and privacy policy of Stichting Modal (Dutch foundation, The Hague); "Eurosky is Modal’s programme to build sovereign social infrastructure for Europe"; launch of mu on 11 June 2026; public repository of mu as a fork of bluesky-social/social-app; mu moderation rules ("We ingest the moderation labels published by Bluesky Social and apply them on mu by default") and its verification programme ("verification should never be paid for and should be primarily via social proof"; "this layer is harder and we don’t yet have a solution for it").
Blacksky: a project driven by Rudy Fraser, featuring a PDS, relay, client, its own moderation service ("community-determined guidelines independent of Bluesky’s moderation policies"), and an alternative implementation of the protocol.
Comparison: X verification linked to subscription since November 2022, with the removal of legacy badges on 20 April 2023; Meta Verified announced on 19 February 2023, with authentication via official documentation.
Migration: official instructions from Eurosky, https://eurosky.tech/accounts/migrate/ (EU-HAUL tool). The steps gathered here are a translation and summary of that documentation.
