Post #3334339
2026-06-16 18:13 UTC
Mastodon (and fedi) instance sign-up idea: Allow instances to use an arbitrary external system to qualify new account requests.
The idea is, the current account application process on Mastodon is essentially unworkable, in the age of AI, and the coming age of agentic AI. It's far too easy to bury admins/mods under a barrage of almost-real-looking applications if there's any new-account moderation. This used to be the reasonable balance point between "open registration" and "invite-only," but it is getting difficult to manage now.
So, perhaps we should offer admins the ability to say, "Go to this webpage, and when that page decides you're cool, it'll call into a URL and either create or recommend the requested account." It would be a setting in the Mastodon settings, which describes a URL to call when a new account is requested. It would offer a properly-authenticated URL for the external site to call back with the new account information.
That external site could do anything to validate that a new user meets the instance's requirements. Maybe it's a Captcha. Maybe it's a short questionnaire. Maybe it's a back-and-forth communication with the new user. Maybe it's a brain teaser that's relatively easy for a human, but difficult for AI. Maybe it's something no one has thought of yet. Maybe it's a combination of these things, or a random selection of them. It's up to the admins to create a selection process that fits their server. It provides an option, and it doesn't depend on the Mastodon development process and timeline to address a rapidly-evolving situation.
Fedi is full of excellent, eager software developers, and I guarantee that it wouldn't take very long until there was a pretty cool suite of software available to validate new user applications, which could be installed alongside the Mastodon software package.
It's not going to be trivial to implement, but it's going to be so much simpler and quicker than asking the core Mastodon development team (or any other fedi software team) to implement such a validation system that actually meets any of the needs of the instances which would want to use it.
This is a system that would allow every instance to have a properly tailored sign-up process. It would be relatively easy to add, with a simple API contract. It shouldn't be required, merely offered as an option alongside open sign-up, moderated sign-up, and invite-only sign-up. It would simplify the lives of many admins by making it harder to create crap accounts, and be adaptable as the threat model evolves. It would result in fewer moderator actions. It would lower stress.
Seems like a win, to me.
Replies (0)
No replies.