Google and Windows Live ID open up to OpenID, October 2008
In late October 2008 Microsoft previewed an OpenID provider for Windows Live ID and Google announced limited provider support. What each did and did not offer.
HistoryPublished
At the end of October 2008 two of the world’s largest web companies moved within a day of each other. Microsoft released a technology preview of an OpenID provider for its Windows Live ID accounts, and Google announced limited support as an OpenID provider. The European OpenID blog posted both items on 30 October 2008. This page is a historical retrospective. openideurope.eu is today an independent guide with no connection to Google, Microsoft, the OpenID Foundation or the former OpenID Europe Foundation.
Microsoft: a preview for Windows Live ID
Windows Live ID was Microsoft’s consumer account system. The announcement, which the old blog reposted from a Microsoft team page, said that the company was publicly committing to OpenID and offering a Community Technology Preview of a Windows Live ID OpenID provider. The old blog placed the announcement on the Tuesday of that week at Microsoft’s developer conference, 28 October 2008.
Key details from the repost:
- A provider, not a consumer: anyone with a Windows Live ID could set up an OpenID alias and use it at OpenID 2.0 sites. The listed examples were Plaxo, Pibb, StackOverflow.com and Wikispaces.
- A test environment only: the preview ran in an integration environment separate from production, mainly for relying-party websites and library developers to test interoperability. Accounts there were test accounts, explicitly not permanent and not linked to Microsoft’s real services.
- OpenID 2.0 only: older versions of the protocol were not supported.
- A call to action: developers were asked to try it and report bugs.
So the October 2008 news was a commitment and a test, not a switch that millions of users could flip.
Google: provider-only and by application
Google’s announcement, made on Wednesday 29 October, described support as a provider for the OpenID 2.0 protocol. Site owners could let users log in and register using their existing Google account information, and users would manage linked sites in one central place. The first release was not open to everyone. Developers had to apply through a sign-up form with their site address, and Plaxo and Zoho were named as first sites.
The old blog quoted commentary from the technology press that this was “not OpenID proper”. In a pure OpenID model, a user would type any OpenID, including one from a different provider. Google instead acted as a middleman: it authenticated you itself before passing an assertion on, and did not let people with OpenIDs from other providers sign in to Google’s own services. Microsoft’s design, in the same commentary, allowed the user to drop in a special OpenID URL as identifier, while Google’s approach kept people tied to a Google account.
Why both stayed one-directional
Both companies were willing to be providers, which brought their millions of users into the OpenID world, but neither accepted outside OpenIDs at its own front door. A provider-only model is attractive for a platform: it extends the reach of an account without giving up control. For the OpenID ideal of decentralisation, it was a half-way house. It also meant that the big names helped bring users to OpenID-enabled sites rather than create a genuinely open mesh of providers.
The OAuth hint
One sentence in the Google item points forward. A Google engineer noted that the company was working on combining OpenID with OAuth, the delegated-access protocol. The reason was practical: login on its own tells a site who the user is, but many sites also wanted permission to read data such as contacts. Combining the two would avoid separate steps. This line of thought ended years later in OpenID Connect, which layers identity on top of OAuth 2.0. The difference between the two is explained in OpenID vs OAuth, and the transition is told in From OpenID to OpenID Connect.
What came next
Reference sources say Google and Yahoo ultimately discontinued active OpenID 2.0 support, and Stack Overflow, one of the first relying parties named in the Microsoft list, ended OpenID login in March 2018 because of low use. Meanwhile, social login from other platforms had grown fast; see Why OpenID 2.0 faded. The earlier, user-count-focused episode is in Yahoo becomes an OpenID provider in 2008, and the full chronology in the OpenID timeline.
More in History
Clavid 2008: Switzerland's first OpenID identity provider
Clavid, a Swiss OpenID provider, added smart cards, YubiKey, fingerprints and client certificates in 2008. What it built, why it mattered and what became of it.
Facebook Connect vs OpenID: how social login won
Facebook Connect arrived in 2008 as OpenID was gaining support. Why a single branded button beat an open standard, and what social login costs users today.
Five lessons from OpenID for the EU Digital Identity Wallet
What the rise and fall of OpenID 2.0 teaches the EU wallet: usability, both sides of the market, phishing, assurance and who sees your logins.
From Microsoft Passport to passkeys: 25 years of SSO
From Microsoft Passport and the Liberty Alliance to OpenID, social login, FIDO2 and passkeys: how the dream of one safe login for everything changed form.
From OpenID to the EU wallet: the road to user-controlled ID
OpenID promised to put users in charge of their identity in 2005. The EU Digital Identity Wallet is the state-backed attempt, built on OpenID4VP and OpenID4VCI.
Google, IBM, Microsoft, Yahoo join the OpenID Foundation
On 7 February 2008 Google, IBM, Microsoft, VeriSign and Yahoo became corporate board members of the OpenID Foundation. What it meant and how to read the data.