The URL nobody mentions in the onboarding email

Mastodon runs on ActivityPub, the W3C-standardised protocol for decentralised social networking, but it quietly exposes a second, older format alongside it. Append .rss to any public Mastodon profile URL — mastodon.social/@username.rss, for instance — and the server returns a valid RSS 2.0 feed containing that account's public posts, complete with timestamps, content, and links. No API key, no OAuth handshake, no developer account required.

The feed is not hidden, exactly, but Mastodon's own documentation treats it as a footnote. Each item corresponds to one public toot (the platform's term for a post), rendered as plain text stripped of reply context. Boosts — Mastodon's equivalent of retweets — do not appear; only original posts and self-replies do. Media attachments surface as enclosed URLs rather than inline embeds. What arrives in a feed reader is closer to a curated writing stream than a social timeline.

Adult leaning over a laptop showing a Feedly unread list several hundred items long, desk lamp casting warm light on the screen
A laptop, a newspaper and a pair of headphones on one desk. Three delivery routes for the same reporting, and only one of them is a feed.Photo: Beyzanur K. / Pexels
Feed reader export dialog on a monitor screen showing OPML file download prompt, adult hand on mouse
Moving between readers is a file transfer, not a migration. OPML carries the URLs; read state, starred items and folders mostly stay behind.Photo: SHVETS production / Pexels

The practical upshot is that any feed reader capable of polling an RSS URL — Feedly, Inoreader, NewsBlur, or a self-hosted instance of Miniflux — can subscribe to a Mastodon account without the subscriber having a Mastodon account of their own. Someone who abandoned federated social networks after the Twitter migrations of 2022 and 2023 can still follow a particular researcher, journalist, or institution through infrastructure that predates Mastodon by nearly two decades.

What the feed cannot deliver is interaction. Replies, favourites, and boosts travel through ActivityPub's federated delivery system, not through the RSS layer. The feed is read-only, passive, and polling-based — the opposite of ActivityPub's push model. Conditional GET headers work as expected: a well-configured feed reader sends ETag or Last-Modified values and receives a 304 Not Modified when nothing has changed, keeping bandwidth consumption low.

From the record

How the URL works

  • Mastodon profile URL patternhttps://[instance]/@[username]
  • RSS feed URL patternappend .rss to the profile URL: https://[instance]/@[username].rss
  • No authentication required for public accounts; private/followers-only accounts return an empty or inaccessible feed

What makes it into the feed vs. what doesn't

  • Included: original posts, self-replies, public content with timestamps and links
  • Excluded: boosts (retoots), replies to other accounts, followers-only posts
  • Media: appears as enclosed URLs, not embedded inline

This architecture illustrates a point worth stating plainly: federated social protocols and RSS are not competing solutions to the same problem. ActivityPub handles the social graph — who follows whom, how replies thread, how boosts propagate across instances. RSS handles consumption — letting readers outside that graph receive public content on their own schedule, through their own tooling. The two layers complement rather than replace each other, and Mastodon's design, intentionally or not, encodes exactly that division of labour into its URL structure.

For publishers and journalists who post substantively to Mastodon, the RSS feed is a distribution channel that requires no additional configuration. The account already exists. The feed already works. The only question is whether readers know to look for it.