Facebook Connect vs OpenID: how social login won
Facebook Connect arrived in 2008 as OpenID was gaining support. Why a single branded button beat an open standard, and what social login costs users today.
HistoryPublished
In 2008 two ideas for ‘one login for many websites’ were running side by side. One was an open standard, OpenID. The other was a product from the biggest social network, Facebook Connect. Within a few years the product had won. The story explains much of what we now take for granted when a website offers ‘Continue with’ buttons.
Two ways to the same goal
OpenID was a protocol. You picked any provider, or ran your own, and a website that supported OpenID would let you sign in with it. Nobody owned the system. The cost was choice: the user had to know which provider they had and, in the original form, often to enter an identifier such as a web address. OpenID 2.0 describes the mechanics.
Facebook Connect was a product. Facebook unveiled it at its developer conference in July 2008 and made it widely available in December 2008. A website added a Facebook button, and visitors who were already logged in to Facebook could sign in with one click. The site also received a name, a photo and, with consent, the user’s friends. There was one provider and one button, and the brand was already familiar.
Why the button won
Several things combined.
- A single choice. ‘Sign in with Facebook’ asked no questions. OpenID’s problem was often called the ‘which provider?’ problem. Users did not remember what their OpenID was, or even that they had one. The detail is covered in Why OpenID 2.0 faded.
- Rich data and social features. A site wanted more than proof of login. It wanted a profile and a social graph. Facebook delivered both. OpenID’s attribute exchange was optional and thinly supported.
- A company pushing it. Facebook had developers, documentation, support and a commercial interest in being the identity layer of the web. OpenID depended on volunteers and on corporate members whose priorities differed.
- Familiarity. People already used Facebook every day, so logging in with it felt natural.
OpenID did not ignore Facebook
OpenID’s leaders did try to connect the two worlds. Facebook joined the OpenID Foundation in February 2009 and launched relying-party support in May 2009, which meant users could sign in to Facebook with an OpenID. That was symbolic more than decisive. The Facebook button, not OpenID, remained the way most sites integrated with the network. Meanwhile Google, Yahoo and Microsoft had joined OpenID in 2008, as described in Big tech joins the OpenID Foundation, but a provider only helps when websites accept its logins, and many sites were slow to add OpenID buttons.
One small 2008 detail shows how quickly the market shifted. In September 2008 the password manager Passpack added Facebook to its list of accepted third-party logins, next to Google, Windows Live and Yahoo. See Passpack and OpenID in 2008.
What it cost
Social login brought convenience, but also dependency. If your account at the provider is suspended, you may lose access to every site that used it. The provider can see which sites you use. Sites may receive more profile data than they need. After a series of privacy scandals around 2018, Facebook tightened what its platform shared with outside apps, and many sites reconsidered how much they relied on one network’s login.
The design question that OpenID had asked, who should hold your identity, did not go away. Apple answered with Sign in with Apple, which lets users hide their email address, and the EU answered with the wallet, where the state and the user, not an advertising platform, hold the credentials.
How it works now
Under every modern social-login button sits OAuth 2.0 for permissions and OpenID Connect for the identity statement. In other words, the open standard survived, but as the plumbing of the commercial buttons. A practical guide to using them safely is Sign in with Google or Apple. For the dates, see the OpenID timeline.
Facts on dates come from public records of Facebook’s developer platform and the OpenID Foundation’s history, as summarised in October 2026.
More in History
Clavid 2008: Switzerland's first OpenID identity provider
Clavid, a Swiss OpenID provider, added smart cards, YubiKey, fingerprints and client certificates in 2008. What it built, why it mattered and what became of it.
Five lessons from OpenID for the EU Digital Identity Wallet
What the rise and fall of OpenID 2.0 teaches the EU wallet: usability, both sides of the market, phishing, assurance and who sees your logins.
From Microsoft Passport to passkeys: 25 years of SSO
From Microsoft Passport and the Liberty Alliance to OpenID, social login, FIDO2 and passkeys: how the dream of one safe login for everything changed form.
From OpenID to OpenID Connect: what changed in 2014
OpenID Connect replaced OpenID 2.0 in February 2014. What was kept, what was thrown away, and why building login on top of OAuth 2.0 finally worked.
From OpenID to the EU wallet: the road to user-controlled ID
OpenID promised to put users in charge of their identity in 2005. The EU Digital Identity Wallet is the state-backed attempt, built on OpenID4VP and OpenID4VCI.
Google and Windows Live ID open up to OpenID, October 2008
In late October 2008 Microsoft previewed an OpenID provider for Windows Live ID and Google announced limited provider support. What each did and did not offer.