Andrew Mercer
on this page

What it is

Mastodon is open-source social-networking server software — the single most widely deployed implementation of [[activitypub|ActivityPub]], and the piece of software most people actually mean when they say "the fediverse," even though the fediverse is bigger than Mastodon alone. It's important to keep the two separate: ActivityPub is the protocol; Mastodon is one application built on it, the way Chrome is one browser built on HTTP. Understanding what's Mastodon-specific versus what's protocol-mandated matters, because Mastodon has made a lot of product decisions ActivityPub itself doesn't require.

How it federates, concretely

Every Mastodon instance is a full ActivityPub server: signing up gives you an actor with an inbox and outbox, and every follow, boost, favorite, and reply is transmitted as an ActivityPub activity. Under the hood, a typical post's journey looks like this:

  1. You post a status; it's stored in Mastodon's PostgreSQL database.
  2. Distribution to local followers happens via Redis (fast, in-process).
  3. Distribution to remote followers — the actual federation step — happens asynchronously via background jobs (Sidekiq), which serialize the post as an ActivityStreams Create activity and deliver it to each remote server's inbox.
  4. Receiving servers verify the request (HTTP Signatures over the request, tying it cryptographically to the sending actor's key) before accepting and storing it.

This asynchronous, queued delivery is why federation between instances can lag by seconds to minutes under load, and why a struggling instance can visibly fall behind on delivering (or receiving) posts.

What Mastodon adds beyond bare ActivityPub

ActivityPub says nothing about UI conventions, character limits, or content-warning semantics — those are all Mastodon product decisions that other ActivityPub apps may or may not share:

  • Content warnings (CWs): a summary field shown before the post body is revealed; a Mastodon convention, not an ActivityPub requirement, though widely adopted across the fediverse now.
  • Post visibility levels: Public, Unlisted (public but excluded from trending/discovery), Followers-only, and Direct — a layered privacy model that isn't part of the base protocol.
  • Lists and filters: client-side organization tools with no federation implications.
  • Account migration: moving your account to a new instance while redirecting your existing followers there automatically — has to be configured in advance on both the old and new account, and doesn't carry your post history.
  • Quote posts: shipped in Mastodon 4.5 (late 2025) after years of the team deliberately avoiding the feature over concerns it would enable "dunking" (quoting to mock out of context). The shipped version includes granular author controls — quoting can be disabled globally via Posting Defaults or per-post, quoted authors are notified, and they can detach their post from someone else's quote after the fact. Because ActivityPub has no native quote concept, Mastodon is working toward standardizing this cross-implementation via FEP-044f ("Object Links") so other fediverse apps can eventually verify and render Mastodon quotes correctly.
  • Mastodon 4.5 also added Fetch All Replies (periodically pulling in replies your instance hadn't seen yet — a real practical gap in pure push-based federation) and admin-side Targeted Blocking by partial username match.

Identity and moderation, Mastodon-specific detail

Mastodon inherits ActivityPub's instance-bound identity model in full: @[email protected] is your whole identity, and it doesn't survive your instance disappearing unless migration was set up beforehand. Mastodon's moderation tooling is what most fediverse admins actually use day to day: per-server rule sets, a reports queue, and — critically — defederation ("suspend" or "limit" a remote domain), which is how most large-scale bad-actor problems on the fediverse have actually been handled historically, rather than through any centralized enforcement.

Governance

Mastodon the software is developed by Mastodon gGmbH, a German non-profit; the project has taken deliberate steps to structure itself so no single company can unilaterally control the fediverse (most notably, moving Mastodon's governance toward a more foundation-like structure in recent years, distinct from how, say, Bluesky is a for-profit PBC controlling the dominant atproto app). Mastodon doesn't own the fediverse — it's simply, by a wide margin, its most popular resident.

Strengths and weaknesses

Strengths: mature, actively developed, the largest ActivityPub deployment by user count and instance count, good moderation tooling for admins, strong content-warning/CW culture norms.

Weaknesses: inherits ActivityPub's instance-bound identity problem; asynchronous federation can lag noticeably; discovery is weaker than algorithmic platforms by design (no global public algorithm, which is a feature to some users and a limitation to others); running a healthy instance is real, ongoing, often uncompensated admin labor.

Further reading

in this section
* install mastdon