[HN Gopher] Colibri - chat platform built on the AT Protocol for...
       ___________________________________________________________________
        
       Colibri - chat platform built on the AT Protocol for communities
       big and small
        
       Author : todotask2
       Score  : 94 points
       Date   : 2026-03-26 17:29 UTC (5 hours ago)
        
 (HTM) web link (colibri.social)
 (TXT) w3m dump (colibri.social)
        
       | louisescher wrote:
       | Hi, person behind the project here, thanks for the cross-post!
        
         | todotask2 wrote:
         | You're welcome! Cool project!
        
           | louisescher wrote:
           | Ty!
        
         | em-bee wrote:
         | where can those of us who are not on bluesky get an invite code
         | for an account?
        
           | louisescher wrote:
           | Feel free to E-Mail me via the PDS's account:
           | pds@colibri.social
           | 
           | I'll send you a code!
        
       | sensen wrote:
       | This looks neat, but should I be concerned about the permissions
       | this is requesting for my account? Bluesky: Manage your profile,
       | posts, likes and follows
        
         | louisescher wrote:
         | Hi! We're doing that to allow you to update your profile from
         | within the app. Not doing anything else besides that. If you
         | have concerns, take a look at the source code:
         | https://github.com/colibri-social/colibri.social
        
           | czbond wrote:
           | Very interesting project.
           | 
           | From a product uptake perspective, I could suggest that since
           | a user is still building trust when they begin use - to only
           | require as few permissions as needed. I'd punt that profile
           | update requirement out personally for another method later.
           | 
           | An example might be when a user has used your app for N
           | sessions, or after N months.
        
             | iamnothere wrote:
             | They should prompt the user for permission when they use a
             | feature that requires it, explain why, and allow them to
             | cancel if desired. Have seen this pattern used many times
             | elsewhere.
        
               | louisescher wrote:
               | Good idea, will implement that! Maybe a button or
               | something to refresh your permissions when/if you want to
               | edit your profile via Colibri makes sense.
        
       | imiric wrote:
       | Interesting project, but...
       | 
       | > BUILT ON OPEN STANDARDS. PRIVATE WHEN NEEDED.
       | 
       | > Running a private group chat? As soon as the AT protocol
       | supports private data, we'll work on implementing it and giving
       | you the option to create private communities.
       | 
       | Not exactly "private when needed" then, is it? It's disingenuous
       | to even mention this in the marketing copy.
        
         | louisescher wrote:
         | Valid point! I'll get that section removed for now and either
         | reword it later, or re-add when the protocol supports it.
        
       | avtar wrote:
       | Please consider adding screenshots of the UI that provide an idea
       | of what the experience will be like without having to log in
       | using Bluesky or other credentials.
        
         | singpolyma3 wrote:
         | I assume it looks the same as literally every other chat app
        
           | Muhammad523 wrote:
           | Yeah. Lots of discord-like free-software(as in freedom) chat
           | apps are spawning. I think it's clear that whichever becomes
           | the most popular will not be about who has better code but
           | rather about who manages to get a stronger community around
           | their project.
        
         | louisescher wrote:
         | Done! Thanks for the suggestion, that's a good idea.
        
           | avtar wrote:
           | Thanks for the quick fix :) Nice to see more Discord
           | alternatives these days.
           | 
           | A few other landing page issues if you feel like addressing
           | them:
           | 
           | - Attempting to navigate with the Tab key results in tab
           | order following nav elements once, where focus indicators
           | aren't visible, and then the same elements get iterated over
           | again but this time focus indicators are visible.
           | 
           | - Tab order doesn't include screenshots and jumps to the FAQ
           | 
           | - Clicking a thumbnail shows the larger image but without any
           | elements for closing the overlay
           | 
           | - Pressing Esc doesn't close the overlay
           | 
           | - No skip links on any of the pages
        
             | louisescher wrote:
             | I don't know how I can keep forgetting about keyboard
             | users. Thanks for bringing this to my attention, I'm
             | working on it!
        
       | isodev wrote:
       | "Your data isn't trapped on our servers" - where is it then? Who
       | can access it?
       | 
       | "Open social" is so much bs compressed in a couple of buzzwords.
        
         | tjuene wrote:
         | > where is it then?
         | 
         | it might be on https://bsky.social, https://npmx.dev/pds or
         | sitting next to your router in your living room in the form of
         | a raspberry pi (https://atproto.com/guides/self-hosting)
        
           | isodev wrote:
           | But that's not where you want your chats now is it? E2EE? And
           | how does it keep it all private since apparently the Bluesky
           | bros haven't figured that part out?
        
             | louisescher wrote:
             | https://colibri.social/faq#where-is-my-data-stored I've
             | just added a new FAQ entry to explain this in a bit more
             | detail.
             | 
             | > But that's not where you want your chats now is it? E2EE?
             | And how does it keep it all private since apparently the
             | Bluesky bros haven't figured that part out?
             | 
             | It honestly depends. Right now, Colibri is meant to
             | function for communities that are public anyway. If you're
             | a streamer, an open source dev community, Colibri can help
             | you with talking to people who don't want to be locked in
             | by big corporations. As the E2EE and private data, the
             | Bluesky people have posted a new proposal for that only a
             | few days ago, which I'm already thinking about how to
             | implement: https://dholms.leaflet.pub/3mhj6bcqats2o
             | 
             | But, yes, for now, chats are public. Private data will
             | hopefully be a thing soon on the network.
        
               | eximius wrote:
               | This probably needs a bigger callout. A user who isn't
               | familiar with ATProto doesn't even know to ask this
               | question and the design space from its contemporaries
               | (e.g., discord, slack, etc) suggests that chats are
               | nominally private if folks aren't a member of the
               | channel.
               | 
               | It's a very cool product but you have to let people know
               | their messages aren't private.
        
               | louisescher wrote:
               | Yep, good feedback. I'll look into it. Will add a new
               | section on the landing page or something.
               | 
               | Edit: Section has been added!
        
       | iamnothere wrote:
       | Thanks for building this, UX is nice and should encourage people
       | to switch from Discord. Bsky only is a bit disappointing as it is
       | still heavily centralized. I would love to see a system like this
       | that can also set up channels over Nostr and the Fediverse.
       | Fragmentation is starting to become an issue with decentralized
       | and federated social.
        
         | louisescher wrote:
         | We've taken a look at co-supporting ActivityPub as well
         | actually! And yeah, the fragmentation is an issue. But I
         | honestly think we might see at lease some level of interop
         | between these fragments in the coming years, even if it's just
         | some parts of the protocols and specs going in the same
         | direction.
        
       | jonashus wrote:
       | Where is data stored? Bluesky? My PDS? Your PDS, for free?
        
         | louisescher wrote:
         | Hi, I've just added an FAQ entry about this:
         | https://colibri.social/faq#where-is-my-data-stored
         | 
         | Also, feel free to DM me (@colibri.social) on Bluesky if you
         | want to migrate to the Colibri PDS! We do host one ourselves.
        
           | the_axiom wrote:
           | Only my own messages are in my PDS? Or the entire chat?
           | 
           | How is the chat displayed if messages are scattered among
           | multiple PDSes?
           | 
           | What about the community metadata, where is it stored?
        
             | louisescher wrote:
             | Your own messages are on your PDS. The chat, the category,
             | community and all metadata are stored on the PDS of the
             | person who created the community. The chat is then
             | displayed via our app view, which keeps a live index of all
             | messages and provides some endpoints to collect them!
        
       | rvrb wrote:
       | Users in a Discord server/local community on tools like Discord
       | naturally expect that their actions within that community are
       | private in so far as they trust everyone in the community
       | (including the operator) to keep it so.
       | 
       | By using ATProto, Colibri fundamentally makes all of your
       | communication within any community completely public to everyone
       | on the internet.
       | 
       | That's fine for something like Twitter, where the product sets
       | the expectation of such a thing. You can imagine how big of an
       | issue this is when you try to do it in a trusted community model.
       | Add on that Discord is used by kids who likely don't know this
       | and you can see why this is dangerous.
       | 
       | I consider this not only just a liability but bordering
       | negligence. It is fundamentally broken, at an architectural level
        
         | em-bee wrote:
         | any discord server that offers public invites is effectively
         | public.
        
           | rvrb wrote:
           | First, the user knows this when joining a public community.
           | 
           | Second, the moderators can choose to remove someone who has
           | joined the community in bad faith.
           | 
           | Third, it is entirely different than broadcasting every
           | single action taken by every single user in every single
           | community on the entire protocol to anyone with one URL.
        
             | em-bee wrote:
             | _the moderators can choose to remove someone who has joined
             | the community in bad faith_
             | 
             | unless you prevent new members from reading the chat
             | history until given permission then they can already read
             | everything before they are kicked out, and they can come
             | back with a different account.
             | 
             | you also can not detect people acting in bad faith if all
             | they do is read.
             | 
             | basically, you can't expect privacy if you don't limit
             | members to people you know and trust. that goes for any
             | group chat, encrypted or not.
             | 
             | i also doubt that discord chatlogs are encrypted on their
             | servers.
        
               | rvrb wrote:
               | What is your point? I feel I made the one you are making
               | before you even responded the first time.
               | 
               | That Discord communications can be exfiltrated in this
               | specific set of circumstances (again, something I already
               | said) does little to change that Colibri is implemented
               | in the least privacy preserving way possible, short of
               | publishing directly to every news and intelligence agency
               | on your behalf, and does little to make that very clear
               | in the first place.
               | 
               | Aside from the fact that there is an authz layer built in
               | to Discord that limits what users can see in any server.
        
           | eximius wrote:
           | Private channels in public servers exist. I'm almost entirely
           | on private servers.
        
         | consumer451 wrote:
         | I agree that is borderline negligence, and by far the biggest
         | issue with AT and Bsky. Here is what I believe to be the most
         | recent discussion on that topic:
         | 
         | https://github.com/bluesky-social/atproto/discussions/3363
        
           | theturtletalks wrote:
           | Having something like circles from the Google+ days would be
           | needed if ATProto is going to go anywhere. Is it possible in
           | the protocol?
        
         | louisescher wrote:
         | Fair point! A different user has already pointed out that this
         | isn't disclosed enough on the landing page, and I'll be adding
         | a section to clarify that, both on there and in the app itself.
         | 
         | I think one of the replies here already linked the current
         | proposal for private data spaces, which I'm hoping will become
         | implemented later this year. At that point, people will have
         | the option of either having their community be 100% public, or
         | confined to a more Discord-style data storage, where people can
         | still join, but not everyone can "just read" the messages
        
           | steveklabnik wrote:
           | Just want to chime in with, this does feel very slick, but
           | this was the #1 question I had. I could not determine it from
           | your site, and had to try it out to see.
           | 
           | One major criticism of things like Discord is that they're
           | private, so I don't think that it's inherently disqualifying,
           | some people might even prefer it for that reason. But it's
           | very, very important that you're very clear about this, up
           | front.
        
             | louisescher wrote:
             | I really appreciate you chiming in, no matter how slick!
             | New section has been added, lmk if you'd like to see this
             | adjusted further
        
       | jFriedensreich wrote:
       | It's impossible to consider ATproto apps usable until the
       | horrific oauth situation is fixed. It's still not possible to
       | adjust oauth permissions to something restrictive dynamically so
       | every app needs a new account which kind of defeats many of the
       | interop promises, if apps even allow it (colibri requires invite
       | code)
        
       | schlu wrote:
       | I totally understand that words and ideas get reused. But when I
       | see Colibri, I think rest stop on the freeway (autoestrada) here
       | in Portugal!
        
       | wolvoleo wrote:
       | Is there something like this on top of nostr too? I'd much rather
       | see nostr because it's truly open.
        
       | cmxch wrote:
       | So does it have the same hermetically sealed qualities that other
       | atproto implementations have (BlueSky)?
        
         | louisescher wrote:
         | Sorry, not quite sure what you mean when you say "hermetically
         | sealed qualities", could you elaborate?
        
       | ebbi wrote:
       | Is there anything like this but more of a reddit style layout?
       | 
       | I'm on a Facebook group and we're actively trying to get off of
       | all Meta platforms, and wanted to see whether I could start up my
       | own platform using an open source platform - but I think
       | something like Reddit would be more suitable as opposed to a
       | massive chat UI.
        
         | louisescher wrote:
         | Hi! We've got Forum-Style channels planned, similar to
         | Discords, would that work for you? It'd still be a single text
         | channel, and you could have multiple of them per community.
        
           | ebbi wrote:
           | Thanks for the reply! I'm not too familiar with Discords
           | forums so will do a bit of digging
        
       ___________________________________________________________________
       (page generated 2026-03-26 23:00 UTC)