openideurope.eu

OpenID Authentication 2.0 approved in December 2007

In December 2007 the OpenID Foundation finalised OpenID Authentication 2.0 and Attribute Exchange 1.0. What changed, who helped and why it still matters.

HistoryPublished

On 5 December 2007 the OpenID Foundation approved the final version of OpenID Authentication 2.0, together with the OpenID Attribute Exchange 1.0 extension. A post on the then-new European OpenID community website announced it on 6 December 2007. This page is a historical article; openideurope.eu is today an independent guide with no connection to the OpenID Foundation or to the former OpenID Europe Foundation.

What was approved

OpenID started in 2005 as a simple way to prove that you controlled a web address, for instance your blog, without creating yet another password at every site. Version 2.0 was the grown-up form of that idea. Two documents made it final:

  • OpenID Authentication 2.0: the core protocol. A user types an identifier, the site (the relying party) finds the user’s provider, redirects there, and gets back a signed statement that this person controls the identifier.
  • OpenID Attribute Exchange 1.0: an extension for passing profile details such as an email address or a name, with the user’s consent.

For a plain-language walkthrough of how the flow works, see OpenID 2.0: the original decentralised login and What is a relying party?.

What was new compared with 1.x

The earlier 1.x versions were designed around URL logins for blogs. Version 2.0 gathered the improvements that had been developed in 2005 and 2006 into one specification:

  • Better discovery: Yadis and XRI-based discovery let a site find the provider behind an identifier more reliably.
  • Extensions: a clean way to attach additional features, of which Attribute Exchange was the first major one, merging work from an earlier competing protocol.
  • Provider-led login (“directed identity”): a user could simply name the provider and let it pick the identifier, instead of typing a long address. That mattered once big companies such as Yahoo wanted to offer OpenID to millions of accounts.

In plain terms, version 2.0 was meant to make OpenID usable for ordinary people and large organisations, not only for people with personal blogs.

The announcement stressed that many companies had contributed legal expertise: Sun, Symantec, Microsoft, Yahoo, IBM, VeriSign and AOL. The OpenID Foundation, formed in June 2007, had built an intellectual property framework in which contributors promised not to assert patents against those who implement the specification. Large vendors would not build on a protocol with unclear patent rights, so this groundwork helped pave the way for the 2008 wave of adoption. The next article, February 2008: Google, IBM, Microsoft and Yahoo join the OpenID Foundation, shows how it played out.

How the European community reacted

The old European site had only just opened. It had a post dated 24 November 2007 saying the new website was “in the starting block”, and the approval notice was among its first news items. In mid-December 2007 the community’s representatives met after a Paris web conference to discuss “OpenID 2.0 and the development in Europe”, as a short blog entry recorded. For the wider event calendar, see OpenID on tour. A policies page on the site also listed the Authentication 2.0 and Attribute Exchange 1.0 specifications alongside its own draft documents.

What happened to OpenID 2.0

Version 2.0 became the standard of the 2008 peak but never reached ordinary users in large numbers. Typing a URL to log in confused many people, phishing worries were real, and social login buttons from large platforms offered a smoother experience. Major providers gradually withdrew support, and Stack Overflow ended OpenID login in March 2018 citing low use. The reasons are examined in Why OpenID 2.0 faded.

The core idea survived under a different technical base. OpenID Connect, published in 2014, builds on OAuth 2.0 and is the form in which most people use “OpenID” today without noticing. Every date in this story is placed in context in the OpenID timeline. The text of the original specifications remains available from the OpenID Foundation.

More in History