openideurope.eu

SourceForge accepts OpenID logins in 2008

In spring 2008 SourceForge, then the best-known home of open source projects, began accepting OpenID logins. What that meant for developers and the standard.

HistoryPublished

In early May 2008 SourceForge.net, at that time the best-known hosting place for open source projects, announced that visitors could log in with an OpenID. The archived European OpenID blog reported it on 4 May 2008 with enthusiasm. This page is a historical retrospective. openideurope.eu is today an independent guide with no connection to SourceForge, to the OpenID Foundation or to the former OpenID Europe Foundation.

What happened

SourceForge was a central platform for open source software. Developers used it to host code, track bugs, publish downloads and run mailing lists, and almost everyone who contributed to free software had an account there. In spring 2008 the operators added OpenID login. A user with an OpenID from any provider could sign in with it rather than creating a SourceForge password.

The blog post made one technical point clearly. SourceForge was not an OpenID provider. It did not hand out identities. It was a relying party: it accepted identities issued elsewhere. That role is explained in What is a relying party?. The post treated this as the healthier of the two roles for the standard’s health, as it spreads the acceptance of OpenID without making one company the owner of everyone’s identity. It also pointed to a smaller bookmarking service that had stopped offering ordinary registration altogether and accepted only OpenID.

What SourceForge said

The announcement from SourceForge, quoted in the blog post, described OpenID as getting “tremendous traction”. The team said it was happy to join, and that, as a decentralised open source standard, OpenID was “a perfect fit”. They hoped it would make user interaction and participation easier across the whole open source community. The post also linked to a developer who pointed out that SourceForge was now one of the most prominent single sites accepting OpenID, and who explained what advanced options existed for people who wanted to use their SourceForge profile page as their own OpenID.

Why developers were the right audience

OpenID had started inside the blogging world and spread first to technical communities. Open source developers fit the idea well: they were comfortable with URLs as identifiers, they cared about avoiding lock-in to one company, and they already maintained personal sites or profile pages that could serve as an identifier. A large developer site accepting OpenID gave the technology credibility beyond blog comments.

It also sits in a wave of developer-facing adopters. In October 2008, Q&A and community sites were among the first relying parties for new providers; the Google and Windows Live ID story lists several. The pattern was the same: sites for technical audiences first, mass-market sites later and only with large providers behind them.

What users actually saw

The announcement describes the feature rather than the screen, but the standard OpenID flow gives the idea: a user enters an OpenID, is sent to the provider, confirms the sign-in there and comes back to SourceForge logged in, with no new SourceForge password to remember. That sounds unspectacular, but for developers who kept separate accounts on many project pages, forums and tools it was a visible benefit. Because the post describes only the login, we do not know how many accounts were actually linked to an OpenID.

The limits of the relying-party route

A site that accepts OpenID gets a verified identifier, but only if users have one and know how to use it. In 2008 most people did not. A relying party therefore usually kept its password login alongside OpenID, so OpenID rarely replaced anything; it was an extra door. Large providers such as Yahoo improved the odds by turning millions of existing accounts into usable OpenIDs, but the sign-in buttons of the large platforms eventually crowded out the generic OpenID option. Reasons for the decline are collected in Why OpenID 2.0 faded.

What is the situation today?

OpenID 2.0, the protocol SourceForge used, has been retired by most large providers, and reference works mention that Stack Overflow ended OpenID support in March 2018 because few people used it. We have not checked whether SourceForge still supports OpenID today and do not claim that it does. Sites that want a single login for many services now typically use single sign-on built on OpenID Connect, or passkeys. The OpenID timeline shows where this episode sits in the larger story.

More in History