Introduction
troposphere is the AT Protocol side of Coop, ROOST’s
open-source trust & safety platform. Together they are a full alternative to
Ozone: troposphere ingests AT Protocol content into
Coop, signs and serves moderation labels (the standard subscribeLabels firehose and
queryLabels endpoint), routes user reports into Coop’s review queue, and enforces takedowns on
your PDS.
Coop is the moderation tool: where you set up your own policies, rules, and actions, and where your reviewers work. troposphere is the atproto plumbing it uses. Coop stays generic and holds no atproto-specific code, so troposphere works for any AT Protocol project regardless of its lexicons, PDS, or AppView.
About this project. troposphere and this documentation were generated by Claude Code, Anthropic’s agentic coding tool. Spot something wrong or unclear? Reach out to @julietshen.online on Bluesky, or open a pull request.
Who this is for
- A project on the AT Protocol that wants trust & safety on Coop: content ingested into a review queue, labels published under its own signing key, reports triaged, takedowns enforced.
- Any such project regardless of its stack: custom lexicons, its own PDS, its own AppView. See Building on the AT Protocol.
- Teams evaluating an alternative to running Ozone.
Not using Coop? The endpoints are plain authenticated HTTP, so other tooling can call them too; see Driving it from a moderation backend.
What it does today
- Ingests AT Protocol content (Jetstream) into Coop’s item intake (
npm run ingest). - Signs labels with a secp256k1 key, verifiable against the labeler’s DID.
- Serves
com.atproto.label.queryLabels(public HTTP). - Serves
com.atproto.label.subscribeLabels(WebSocket firehose) with cursor backfill and a live tail. - Exposes
POST /admin/labels(create/negate) andPOST /coop/action(Coop’s action shape). - Accepts
com.atproto.moderation.createReportfrom any AT Protocol AppView, enriches it, and forwards it to Coop’s review queue. - Enforces takedowns and restores on your own PDS via
POST /admin/enforce. - Persists labels and reports in Postgres, with a monotonic sequence for firehose cursors.
What it does not do
troposphere does not decide what to label or take down. That happens in Coop, from the policies and actions you configure and the reviewers who work there; Coop then calls troposphere’s APIs to carry the decision out. Identity provisioning helpers and multi-tenant operation are on the roadmap.
The fastest way to see it work is Getting started.