Bluesky AT Protocol Rate Limits 2026 (Full Breakdown)

Bluesky's AT Protocol rate limits an account to 5,000 points per hour and 35,000 points per day for repository record operations, on top of a separate cap of 3,000 HTTP API requests per 5 minutes per IP address. In practical terms, that works out to roughly 1,666 new records per hour and 11,666 per day, since each created post, like, follow, or repost consumes points rather than counting as a flat "one action" against the limit.
How the point system actually works
Every write to your Bluesky repository (a post, like, follow, repost, or block) costs points rather than a flat unit:
- Creating a record costs 3 points
- Updating a record costs 2 points
- Deleting a record costs 1 point
So a single post costs 3 points, meaning the 5,000 point hourly ceiling supports far more than 5,000 posts. It is designed to absorb heavy automated activity, not just casual posting, which is one reason bots and scheduling tools rarely bump into it under normal use.
What happens when you hit the limit
Requests that cross either the point based repository limit or the HTTP request limit get a 429 "Too Many Requests" response. Bluesky's API also returns rate limit headers on responses so developers can track how close an app is running to the ceiling and back off automatically instead of guessing.
Why this matters for automation and AI agents
Bluesky's AT Protocol is an open, federated system with no app review process gatekeeping API access, unlike Meta or X. Anyone can register an app password or OAuth client and start posting programmatically within minutes, which is why it has become a favorite platform for developers building bots, cross-posting tools, and AI agents. There is no waiting period, no developer application form, and no platform reviewer deciding whether your use case qualifies.
That accessibility is also why Bluesky is one of the ten platforms Posted Once schedules to through its own MCP server and REST API, letting AI agents and automated workflows post to Bluesky the same way a human would through the dashboard, without hand rolling AT Protocol authentication.
How this compares to other platforms
Meta and X both gate API access behind a developer application, an approval wait that can run days or weeks, and pricing tiers that charge per call once you are approved. Bluesky skips all three steps. You generate an app password or set up OAuth directly from your account settings, and you are making authenticated requests within minutes, at no cost, with no reviewer deciding whether your project qualifies. For a solo developer testing an idea, that difference alone can be the reason a project ships on Bluesky first and other platforms later, if at all.
Practical takeaway
For a scheduling tool or a single active account, these limits are generous enough that you will not notice them in normal daily use. They only become relevant if you are running high volume automation, bulk backfilling old content, or building a bot network. If you schedule Bluesky posts manually or through a Bluesky scheduler like Posted Once, check your post length against the Bluesky character counter and you will stay well inside these limits without thinking about them.
Schedule to every platform at once
Posted Once publishes your content to all 10 social networks from one place.
Start free trialKeep reading
Google Business Description Limit 2026 (750 Characters)
specsFacebook Upload File Size Limit 2026
specsFacebook Video Dimensions Guide 2026 (Feed, Reels, Stories)
specsFacebook Story Dimensions 2026 (1080x1920)
specsFacebook Bio and About Length Guide 2026
specsBluesky Video Length Limit 2026 (3 Min)