Jabber.org and OpenID in 2008: XMPP meets web login
In March 2008 the Jabber.org website began accepting OpenID logins. What that meant for open instant messaging, and what became of Jabber.org since.
HistoryPublished
In March 2008 the website of Jabber.org started to accept OpenID logins. The news reached the OpenID Europe blog on 19 March 2008, which said the login had been available since 8 March. It was a small item in a busy spring of OpenID announcements, but it is a neat example of two open, decentralised ideas finding each other.
What was announced
Jabber.org was, and still describes itself as, the original public service based on XMPP, the Extensible Messaging and Presence Protocol. In 2008 the archived blog post summed the project up as an open technology for instant messaging, a decentralised network of IM services and a set of stable standards for real-time communication published by the IETF. The post also stressed a point that made XMPP different from most chat networks of the time: if you already had an account at an XMPP-enabled service, you could use any compatible client to talk to people on other servers, or run a server of your own.
The OpenID change was narrower than it may sound. It let visitors sign in to the Jabber.org website with an OpenID instead of a separate website account. It did not turn OpenID into a login method for the chat protocol itself. XMPP continued to authenticate users with its own mechanisms, as it still does.
Why the fit was natural
OpenID and XMPP shared a design philosophy. Neither depended on one company’s servers. An OpenID could come from any provider, or from your own domain, in the same way an XMPP address could live on any server. Both were published as open specifications, and the XMPP core was an IETF standard (RFC 3920 in 2004, replaced by RFC 6120 in 2011). The XMPP Standards Foundation, which develops extensions to the protocol, belongs to the same family of open-standards communities.
For a project that valued federation, accepting a login from anywhere was consistent. The alternative, another username and password stored on yet another site, was exactly what OpenID wanted to end. The general idea is explained in identity federation and in the later single sign-on guide.
What happened to Jabber.org
The service itself has had a long and not always smooth life. Public records describe a launch in 1999 as a test bed for the original Jabber server, a move to different server software over the years, and, in 2013, an end to new account registration while existing XMPP accounts from other services remained usable. In 2023 the service migrated to the Prosody server software, and its homepage now credits the infrastructure of the messaging company JMP.chat, volunteers and the Prosody team as sponsors.
Open instant messaging also lost its largest federated member. Google Talk once interoperated with XMPP servers, but Google moved its chat products away from open federation in the following years, and the XMPP network shrank to a community of enthusiasts, companies and a growing number of self-hosters.
What the episode shows
Two lessons stand out. First, OpenID was most welcome where users already cared about decentralisation. Open-source communities such as Jabber.org and SourceForge added it early, and later adopters such as Stack Overflow, which ended OpenID support in 2018 citing low usage, dropped it again. Why OpenID 2.0 faded looks at the reasons.
Second, federation survives when it is easy to run and has a clear user benefit. XMPP is still alive. OpenID 2.0, the protocol behind the 2008 login, is described in OpenID 2.0 and is effectively retired. Its successor, OpenID Connect, now sits behind most single sign-on buttons.
Today
If you want to try open messaging, an XMPP account from any current provider will do, and modern clients support current encryption standards. For the full sequence of milestones around this episode, see the OpenID timeline. For how OpenID Europe reported on other services that year, read the stories of Yahoo and Passpack.
Facts about Jabber.org as of October 2026, from the service’s own homepage and public records. The original 2008 announcement is preserved in the Internet Archive.
More in History
Clavid 2008: Switzerland's first OpenID identity provider
Clavid, a Swiss OpenID provider, added smart cards, YubiKey, fingerprints and client certificates in 2008. What it built, why it mattered and what became of it.
Facebook Connect vs OpenID: how social login won
Facebook Connect arrived in 2008 as OpenID was gaining support. Why a single branded button beat an open standard, and what social login costs users today.
Five lessons from OpenID for the EU Digital Identity Wallet
What the rise and fall of OpenID 2.0 teaches the EU wallet: usability, both sides of the market, phishing, assurance and who sees your logins.
From Microsoft Passport to passkeys: 25 years of SSO
From Microsoft Passport and the Liberty Alliance to OpenID, social login, FIDO2 and passkeys: how the dream of one safe login for everything changed form.
From OpenID to OpenID Connect: what changed in 2014
OpenID Connect replaced OpenID 2.0 in February 2014. What was kept, what was thrown away, and why building login on top of OAuth 2.0 finally worked.
From OpenID to the EU wallet: the road to user-controlled ID
OpenID promised to put users in charge of their identity in 2005. The EU Digital Identity Wallet is the state-backed attempt, built on OpenID4VP and OpenID4VCI.